The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.
History

Wed, 15 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 23:30:00 +0000

Type Values Removed Values Added
Description The ip_import_acl_csv request in GestiolP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data. The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

Tue, 14 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description The ip_import_acl_csv request in GestiolP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-14T00:00:00

Updated: 2025-01-15T19:11:06.155Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-50859

cve-icon Vulnrichment

Updated: 2025-01-15T19:11:00.733Z

cve-icon NVD

Status : Received

Published: 2025-01-14T22:15:27.453

Modified: 2025-01-15T20:15:28.193

Link: CVE-2024-50859

cve-icon Redhat

No data.