Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-45880
HistoryNov 14, 2023 - 12:00 a.m.

CVE-2023-45880

2023-11-1400:00:00
mitre
github.com
1
gibbonedu
version 25.0.0
directory traversal
report template builder
asset component
templatefiledestination
uploads directory
webroot vulnerability

AI Score

6.9

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

AI Score

6.9

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-45880