Ksenia Security Lares 4.0 version 1.6 contains a URL...
Moderate severity
Unreviewed
Published
Dec 31, 2025
to the GitHub Advisory Database
•
Updated Dec 31, 2025
Description
Published by the National Vulnerability Database
Dec 30, 2025
Published to the GitHub Advisory Database
Dec 31, 2025
Last updated
Dec 31, 2025
Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
References