CVE-2024-50861 is a Stored Cross-Site Scripting (XSS) vulnerability affecting GestioIP v3.5.7. An attacker can inject malicious code into the "TSIG Key" field, which is then stored in the database and executed when viewed by another user. This medium-severity vulnerability (CVSS 6.1) has a low attack complexity and can lead to data exfiltration and Cross-Site Request Forgery (CSRF) attacks. While not currently in CISA's KEV catalog or observed in active exploitation, public exploit code is available via ExploitDB (EDB-52201), though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5.7CPE matchmatch criteria | cpe:2.3:a:gestioip:gestioip:3.5.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.