CVE-2024-24724

9.8CRITICAL

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messeng

게시됨: 4/3/2024업데이트됨: 7/17/2025

설명

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

AI 분석AI 기반

영향받는 제품

gibbonedugibbon

사용 가능한 익스플로잇 (1)

참조