CVE Feed

    Dashboard / CVE / CVE-2024-50857

    CVE-2024-50857

    The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.

    Published:Jan 14, 2025
    Last Modified:Jun 6, 2025
    EPS:Jan 14, 2025
    EPSS Score:0.00219
    CVSS Score:4.8

    Affected Products

    Vendor
    Gestioip
    Product
    Gestioip

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High