Skip to content
Noroxi

GestioIP records

5 published records for vendor gestioip.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 20%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

5 records
  • An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function.

    CriticalCVSS 9.8WeaponizedEPSS 45%

    gestioip · gestioipJan 14, 2025

  • Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF).

    HighCVSS 8.8Proof of conceptEPSS 2%

    gestioip · gestioipJan 14, 2025

  • The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    gestioip · gestioipJan 14, 2025

  • The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS).

    MediumCVSS 4.8Proof of conceptEPSS 1%

    gestioip · gestioipJan 14, 2025

  • The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS.

    MediumCVSS 4.8Proof of conceptEPSS 1%

    gestioip · gestioipJan 14, 2025