CVE-2023-45879
- EPSS 0.46%
- Veröffentlicht 14.11.2023 06:15:29
- Zuletzt bearbeitet 21.11.2024 08:27:32
GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.
CVE-2023-45878
- EPSS 63.11%
- Veröffentlicht 14.11.2023 06:15:29
- Zuletzt bearbeitet 08.01.2025 17:15:14
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a b...
CVE-2023-34599
- EPSS 1.85%
- Veröffentlicht 29.06.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:25
Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.
CVE-2023-34598
- EPSS 44.86%
- Veröffentlicht 29.06.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:24
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.
CVE-2022-27305
- EPSS 1.01%
- Veröffentlicht 25.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:35
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
CVE-2022-23871
- EPSS 0.62%
- Veröffentlicht 03.02.2022 03:15:06
- Zuletzt bearbeitet 21.11.2024 06:49:23
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description paramete...
CVE-2022-22868
- EPSS 0.86%
- Veröffentlicht 28.01.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:34
Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters.
CVE-2021-40214
- EPSS 0.71%
- Veröffentlicht 13.09.2021 12:15:11
- Zuletzt bearbeitet 21.11.2024 06:23:45
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.
CVE-2021-40492
- EPSS 2.28%
- Veröffentlicht 03.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:15
A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).