vendor:
GestioIP
by:
m4xth0r (Maximiliano Belino)
6.1
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: GestioIP
Affected Version From: 3.5.2007
Affected Version To: 3.5.2007
Patch Exists: NO
Related CWE: CVE-2024-50857
CPE: a:gestioip:gestioip:3.5.7
Platforms Tested: Kali Linux
2025
GestioIP 3.5.7 – Authenticated Cross-Site Scripting (XSS) Vulnerability
GestioIP 3.5.7 is prone to an authenticated cross-site scripting vulnerability in the 'ip_do_job' feature. This could allow attackers to perform data exfiltration and cross-site request forgery (CSRF) attacks. The vulnerability can be exploited by injecting malicious scripts into parameters like 'host_id' and 'stored_config'.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user inputs to prevent the execution of malicious scripts. Additionally, implementing content security policy (CSP) headers can help in mitigating XSS attacks.