Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-50858. PoCs published by Maximiliano Belino.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in GestioIP 3.5.7, allowing an attacker to execute actions through an authenticated admin's browser by tricking them into visiting a malicious URL. The provided HTML payload modifies a user's privileges to administrator level.
Description
Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in GestioIP 3.5.7, allowing an attacker to execute actions through an authenticated admin's browser by tricking them into visiting a malicious URL. The provided HTML payload modifies a user's privileges to administrator level.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H