CVE-2023-45880
14.11.2023, 06:15
GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.
| Vendor | Product | Version |
|---|---|---|
| gibbonedu | gibbon | 𝑥 ≤ 25.0.00 |
𝑥
= Vulnerable software versions