CVE-2024-24724

9.8CRITICAL

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messeng

Publicado: 4/3/2024Actualizado: 7/17/2025

Descripción

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

Análisis IAImpulsado por IA

Productos Afectados

gibbonedugibbon

Exploits Disponibles (1)

Referencias