ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.
Fixes

Solution

Software update is unable to patch the vulnerability, please disable the affected website(Relay). For further instructions, please contact the vendor to obtain the security documentation.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T20:55:10.323Z

Reserved: 2024-05-15T02:31:57.684Z

Link: CVE-2024-4894

cve-icon Vulnrichment

Updated: 2024-08-01T20:55:10.323Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T03:15:14.887

Modified: 2024-11-21T09:43:48.647

Link: CVE-2024-4894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:14:40Z