cve/2024/CVE-2024-23759.md
2024-05-25 21:48:12 +02:00

671 B

CVE-2024-23759

Description

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

POC

Reference

Github