Vulnerabilities > Gibbonedu > Gibbon

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-45878 Unspecified vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication.
network
low complexity
gibbonedu
critical
9.8
2023-11-14 CVE-2023-45879 Cross-site Scripting vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.
network
low complexity
gibbonedu CWE-79
5.4
2023-11-14 CVE-2023-45880 Path Traversal vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder.
network
low complexity
gibbonedu CWE-22
7.2
2023-11-14 CVE-2023-45881 Cross-site Scripting vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS.
network
low complexity
gibbonedu CWE-79
6.1
2023-06-29 CVE-2023-34598 Path Traversal vulnerability in Gibbonedu Gibbon 25.0.00
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.
network
low complexity
gibbonedu CWE-22
critical
9.8
2023-06-29 CVE-2023-34599 Cross-site Scripting vulnerability in Gibbonedu Gibbon 25.0.00
Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.
network
low complexity
gibbonedu CWE-79
6.1
2022-05-25 CVE-2022-27305 Session Fixation vulnerability in Gibbonedu Gibbon
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
network
gibbonedu CWE-384
6.8
2022-02-03 CVE-2022-23871 Cross-site Scripting vulnerability in Gibbonedu Gibbon 22.0.01
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description parameters.
network
gibbonedu CWE-79
3.5
2022-01-28 CVE-2022-22868 Cross-site Scripting vulnerability in Gibbonedu Gibbon 22.0.01
Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters.
network
gibbonedu CWE-79
3.5
2021-09-13 CVE-2021-40214 Cross-site Scripting vulnerability in Gibbonedu Gibbon 22.0.00
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.
network
gibbonedu CWE-79
3.5