Gestioip is an open-source IP address management platform whose vulnerability profile centers on web-application security issues, with the recurring weakness classes being cross-site scripting, cross-site request forgery, and unrestricted file uploads. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gestioip over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48760CRITICAL An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites th | Jan 14, 2025 | 9.8 | 74 | NO | YES |
CVE-2024-50858HIGH Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leadi | Jan 14, 2025 | 8.8 | 35 | NO | YES |
CVE-2024-50857MEDIUM The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user | Jan 14, 2025 | 4.8 | 32 | NO | YES |
CVE-2024-50861MEDIUM The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database | Jan 14, 2025 | 6.1 | 28 | NO | YES |
CVE-2024-50859MEDIUM The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response | Jan 14, 2025 | 4.8 | 25 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gestioip.
Media articles that mention a CVE ID that affects a product developed by Gestioip — matched by CVE ID, not by vendor name.