CVE-2024-50861
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.1epss 0.8%
from disclosure to weapon90 days
Published on NVDJan 14
1st PoC+90d
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/52201unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.