Vulnerabilities
Vulnerable Software
Gibbonedu:  >> Gibbon  >> 26.0.00  Security Vulnerabilities
Gibbon before 29.0.00 allows CSRF.
CVSS Score
3.7
EPSS Score
0.0
Published
2025-05-27
Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User Admin/user_manage_editProcess.php.
CVSS Score
3.5
EPSS Score
0.005
Published
2024-11-21
cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.
CVSS Score
6.1
EPSS Score
0.015
Published
2024-09-10
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.
CVSS Score
9.8
EPSS Score
0.392
Published
2024-04-03
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.
CVSS Score
8.8
EPSS Score
0.791
Published
2024-03-23


Contact Us

Shodan ® - All rights reserved