Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.
References
Configurations
No configuration.
History
16 Aug 2024, 16:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-1336 |
03 Apr 2024, 12:38
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Apr 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-03 03:15
Updated : 2024-08-16 16:35
NVD link : CVE-2024-24724
Mitre link : CVE-2024-24724
CVE.ORG link : CVE-2024-24724
JSON object : View
Products Affected
No product.
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine