CVE-2024-28344: Sipwise Next Generation Communication Platform

Low severity, CVSS 3.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.

Affected products

  • Sipwise Next Generation Communication Platform: before mr11.5.1 (fixed in mr11.5.1)

Published 2024-04-10. Last modified 2026-06-17.