CVE-2024-23759
CRITICALGambio <= 4.9.2.0 - Remote Code Execution via Parcelshopfinder AddAddressBookEntry Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-23759.
Includes Metasploit module exploits/multi/http/gambio_unauth_rce_cve_2024_23759.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated PHP deserialization vulnerability in Gambio Online Webshop (CVE-2024-23759) to achieve remote code execution. It uploads a webshell via a crafted serialized payload and executes arbitrary commands.
Description
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
Exploits (1)
This Metasploit module exploits an unauthenticated PHP deserialization vulnerability in Gambio Online Webshop (CVE-2024-23759) to achieve remote code execution. It uploads a webshell via a crafted serialized payload and executes arbitrary commands.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H