CVE-2024-24724

9.8CRITICAL

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messeng

Published: 4/3/2024Updated: 7/17/2025

Description

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

AI AnalysisPowered by AI

Affected Products

gibbonedugibbon

Available Exploits (1)

References