CVE-2024-23759

Publication date

2024-02-12 00:00:00

Family

mitre

State

PUBLISHED

Description

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.