CVE-2024-50859: Gestioip

Medium severity, CVSS 4.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

Affected products

Published 2025-01-14. Last modified 2026-06-17.