CVE-2024-50859: Gestioip
Medium severity, CVSS 4.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.
Affected products
- Gestioip Gestioip: version 3.5.7 only
Published 2025-01-14. Last modified 2026-06-17.