CVE-2024-28345: Sipwise Next Generation Communication Platform

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.

Affected products

  • Sipwise Next Generation Communication Platform: before mr11.5.1 (fixed in mr11.5.1)

Published 2024-04-10. Last modified 2026-06-17.