CVE-2024-4894: Itpison Omicard Edm

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.

Affected products

  • Itpison Omicard Edm: before 6.0 (fixed in 6.0)

Published 2024-05-15. Last modified 2026-06-17.