{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T06:50:59.771","vulnerabilities":[{"cve":{"id":"CVE-2024-50861","sourceIdentifier":"cve@mitre.org","published":"2025-01-14T22:15:27.577","lastModified":"2026-06-17T08:05:08.617","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the \"TSIG Key\" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks."},{"lang":"es","value":" La solicitud ip_mod_dns_key_form.cgi en GestioIP v3.5.7 es vulnerable a XSS almacenado. Un atacante puede inyectar código malicioso en el campo \"TSIG Key\", que se guarda en la base de datos y activa XSS cuando se visualiza, lo que permite la exfiltración de datos y los ataques CSRF."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-15T16:26:38.863103Z","id":"CVE-2024-50861","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gestioip:gestioip:3.5.7:*:*:*:*:*:*:*","matchCriteriaId":"D32EC91F-6E1F-42A2-AA8E-21D694111822"}]}]}],"references":[{"url":"http://www.gestioip.net","source":"cve@mitre.org","tags":["Product"]},{"url":"https://github.com/maxibelino/CVEs/tree/main/CVE-2024-50861","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/muebel/gestioip-docker-compose","source":"cve@mitre.org","tags":["Product"]},{"url":"https://github.com/maxibelino/CVEs/tree/main/CVE-2024-50861","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}}]}