Remote Code Execution Flaw in GestioIP by GestioIP
CVE-2024-48760
9.8CRITICAL
What is CVE-2024-48760?
A vulnerability in GestioIP v3.5.7 permits remote attackers to execute arbitrary code through an insecure file upload mechanism. By uploading a crafted 'perlcmd.cgi' file, an adversary can overwrite the legitimate 'upload.cgi' file, facilitating unauthorized command execution on the server. This poses significant risks to users, making it critical to apply the necessary security measures promptly.