Record summary

CVE-2023-34598 has a selected CVSS score of 9.8 (critical); EIP currently links 3 repository PoCs and 1 Nuclei template.

Description

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 18, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
3
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 26, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

3

Repository PoCs

GitHubmaddsec/CVE-2023-34598Repository PoCby maddsecStars: 3Not analyzed1 file

1009 B

GitHub

PoC details
GitHubLserein/CVE-2023-34598Repository PoCby LsereinStars: 1Not analyzed4 files

150.3 KiB

GitHub

PoC details
GitHubZer0F8th/CVE-2023-34598Repository PoCby Zer0F8thStars: 0Not analyzed2 files

9.2 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALGibbon v25.0.0 - Local File InclusionCVSS 9.8

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) vulnerability where it's possible to include the content of several files present in the installation folder in the server's response.

Impact

The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.

Remediation

Upgrade to a patched version of Gibbon or apply the necessary security patches to mitigate the LFI vulnerability.

WeaknessesCWE-22
AuthorsDhiyaneshDk
Template tagscve2023cvegibbonlfigibboneduvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:gibbonedu:gibbon:25.0.00:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-165631681
Shodan: http.favicon.hash:"-165631681"
FOFA: icon_hash="-165631681"

Source: ProjectDiscovery

References

2