Vulnerabilities > Gibbonedu > Gibbon > 22.0.00

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-45878 Unspecified vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication.
network
low complexity
gibbonedu
critical
9.8
2023-11-14 CVE-2023-45879 Cross-site Scripting vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.
network
low complexity
gibbonedu CWE-79
5.4
2023-11-14 CVE-2023-45880 Path Traversal vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder.
network
low complexity
gibbonedu CWE-22
7.2
2023-11-14 CVE-2023-45881 Cross-site Scripting vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS.
network
low complexity
gibbonedu CWE-79
6.1
2022-05-25 CVE-2022-27305 Session Fixation vulnerability in Gibbonedu Gibbon
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
network
gibbonedu CWE-384
6.8
2021-09-13 CVE-2021-40214 Cross-site Scripting vulnerability in Gibbonedu Gibbon 22.0.00
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.
network
gibbonedu CWE-79
3.5
2021-09-03 CVE-2021-40492 Cross-site Scripting vulnerability in Gibbonedu Gibbon 22.0.00
A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).
network
gibbonedu CWE-79
4.3