CVE Database
/

CVE-2024-50861

Back to search

CVE-2024-50861

Published: Jan 14, 2025

Modified: Jan 15, 2025

PUBLISHED

Description

The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

VendorProductVersions

n/a

n/a

affected
n/a

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now