cve/2024/CVE-2024-23759.md
2024-06-09 00:33:16 +00:00

732 B

CVE-2024-23759

Description

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

POC

Reference

Github