Releases82
Frequency1 month 3 weeks
Last Release
Stars608
Gibbon is a flexible, open source school management platform designed to make life better for teachers, students, parents and leaders.

CVE History

CVEPublishedCVSS v3CVSS v2

Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful exploitation requires Teacher or higher privileges. Exploitation could result in loss of availability of the web application.

Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.

Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges. Exploitation could result in unintended read/write activities to the underlying database.

3.7 LOW

Gibbon before 29.0.00 allows CSRF.

3.5 LOW

Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User Admin/user_manage_editProcess.php.

8.8 HIGH6.8 MEDIUM

Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

4.8 MEDIUM3.5 LOW

Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters.

5.4 MEDIUM3.5 LOW

Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.