The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Tue, 14 Jan 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ip_mod_dns_key_form.cgi request in GestiolP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks. | The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks. |
Tue, 14 Jan 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ip_mod_dns_key_form.cgi request in GestiolP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2025-01-14T00:00:00
Updated: 2025-01-15T16:42:31.035Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-50861
Vulnrichment
Updated: 2025-01-15T16:40:55.955Z
NVD
Status : Received
Published: 2025-01-14T22:15:27.577
Modified: 2025-01-15T17:15:16.257
Link: CVE-2024-50861
Redhat
No data.