CVE-2024-24724

9.8CRITICAL

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messeng

Publicado: 4/3/2024Atualizado: 7/17/2025

Descrição

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

Análise IADesenvolvido por IA

Produtos Afetados

gibbonedugibbon

Exploits Disponíveis (1)

Referências