Vulnerabilities > Gambio > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-12 CVE-2024-23759 Unrestricted Upload of File with Dangerous Type vulnerability in Gambio 4.9.2.0
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
network
low complexity
gambio CWE-434
critical
9.8
2024-02-12 CVE-2024-23761 Server-Side Request Forgery (SSRF) vulnerability in Gambio 4.9.2.0
Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.
network
low complexity
gambio CWE-918
critical
9.8
2024-02-12 CVE-2024-23763 SQL Injection vulnerability in Gambio 4.9.2.0
SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.
network
low complexity
gambio CWE-89
critical
9.8