Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-50859

Опубликовано: 14 янв. 2025
Источник: debian
EPSS Низкий

Описание

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gestioipitppackage

EPSS

Процентиль: 58%
0.00373
Низкий

Связанные уязвимости

CVSS3: 4.8
nvd
около 1 года назад

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

CVSS3: 4.8
github
около 1 года назад

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

EPSS

Процентиль: 58%
0.00373
Низкий