Skip to main content

Vendor/product archive

gibbonedu / gibbon CVEs

Beta · best-effort

16 CVEs tagged to gibbonedu / gibbon3 Critical, 3 High, 8 Medium, 2 Low, 0 Unrated.

CVE-2024-51337

Published Nov 21, 2024

Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gib…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-34831

Published Sep 10, 2024

cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24724

Published Apr 3, 2024

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig tem…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24725

Published Mar 23, 2024

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45881

Published Nov 14, 2023

GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to r…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45880

Published Nov 14, 2023

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination param…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45879

Published Nov 14, 2023

GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45878

Published Nov 14, 2023

GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34599

Published Jun 29, 2023

Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34598

Published Jun 29, 2023

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's respons…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-27305

Published May 25, 2022

Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23871

Published Feb 3, 2022

Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22868

Published Jan 28, 2022

Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40214

Published Sep 13, 2021

Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40492

Published Sep 3, 2021

A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPerson…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1