CVE-2024-48760: exploitation status and patch state
CVE-2024-48760 · CVSS 9.8 CRITICAL · EPSS 45%
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.
Is CVE-2024-48760 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 45%.