CVE-2023-34598
gibbonedu gibbon Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2023-34598 has a selected CVSS score of 9.8 (critical); EIP currently links 3 repository PoCs and 1 Nuclei template.
Description
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Proofs of concept
3Repository PoCs
GitHubmaddsec/CVE-2023-34598Repository PoCby maddsecStars: 3Not analyzed1 file
GitHubLserein/CVE-2023-34598Repository PoCby LsereinStars: 1Not analyzed4 files
GitHubZer0F8th/CVE-2023-34598Repository PoCby Zer0F8thStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALGibbon v25.0.0 - Local File InclusionCVSS 9.8
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) vulnerability where it's possible to include the content of several files present in the installation folder in the server's response.
Impact
The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.
Remediation
Upgrade to a patched version of Gibbon or apply the necessary security patches to mitigate the LFI vulnerability.
Source: ProjectDiscovery