The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gestioip
Gestioip gestioip |
|
CPEs | cpe:2.3:a:gestioip:gestioip:3.5.7:*:*:*:*:*:*:* | |
Vendors & Products |
Gestioip
Gestioip gestioip |
Wed, 15 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Tue, 14 Jan 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ip_mod_dns_key_form.cgi request in GestiolP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks. | The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks. |
Tue, 14 Jan 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ip_mod_dns_key_form.cgi request in GestiolP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-01-14T00:00:00
Updated: 2025-01-15T16:42:31.035Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-50861

Updated: 2025-01-15T16:40:55.955Z

Status : Analyzed
Published: 2025-01-14T22:15:27.577
Modified: 2025-06-06T15:40:35.923
Link: CVE-2024-50861

No data.