Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gibbonedu
Gibbonedu gibbon |
|
| CPEs | cpe:2.3:a:gibbonedu:gibbon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gibbonedu
Gibbonedu gibbon |
Fri, 16 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1336 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-16T15:15:46.527Z
Reserved: 2024-01-27T00:00:00
Link: CVE-2024-24724
Updated: 2024-08-01T23:28:11.891Z
Status : Analyzed
Published: 2024-04-03T03:15:09.173
Modified: 2025-07-17T17:09:42.747
Link: CVE-2024-24724
No data.
OpenCVE Enrichment
No data.
Weaknesses