Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-45881
HistoryNov 14, 2023 - 12:00 a.m.

CVE-2023-45881

2023-11-1400:00:00
mitre
github.com
1
gibbonedu version 25.0.0
xss vulnerability
planner resources.

AI Score

6.7

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute of the bodyfile1 parameter is reflected in the response.

AI Score

6.7

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-45881