CVE-2024-50861
Last modified
CVE-2024-50861 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gestioip | Gestioip | 3.5.7 |
References
- http://www.gestioip.netProduct
- https://github.com/maxibelino/CVEs/tree/main/CVE-2024-50861Exploit, Third Party Advisory
- https://github.com/maxibelino/CVEs/tree/main/CVE-2024-50861Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-50861?
How severe is CVE-2024-50861?
How do I fix CVE-2024-50861?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-50853Tenda G3 v3.0 v15.11.0.20 was discovered to contain a comman…8.8
- CVE-2024-50854Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack …8.8
- CVE-2024-50857The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cr…4.8
- CVE-2024-50858Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cros…8.8
- CVE-2024-50859The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerab…4.8
- CVE-2024-5086The Essential Addons for Elementor PRO – Best Elementor Temp…5.4
- CVE-2024-5087The Minimal Coming Soon – Coming Soon Page plugin for WordPr…5.4
- CVE-2024-5088The Happy Addons for Elementor plugin for WordPress is vulne…5.4
- CVE-2024-5089Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-5090The SiteOrigin Widgets Bundle plugin for WordPress is vulner…5.4
- CVE-2024-5091The SKT Addons for Elementor plugin for WordPress is vulnera…5.4
- CVE-2024-50919Jpress until v5.1.1 has arbitrary file uploads on the window…9.8
Are you affected by CVE-2024-50861?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
