Vulnerability Details CVE-2024-23759
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.644
EPSS Ranking 98.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-23759
-
cpe:2.3:a:gambio:gambio:4.9.2.0