cve/2024/CVE-2024-23759.md
2024-06-18 02:51:15 +02:00

671 B

CVE-2024-23759

Description

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

POC

Reference

Github