gibbonedu.org
https://gibbonedu.org/download CVE-2024-24725
HIGH
Gibbon LMS < v26.0.00 - Authenticated RCE
Record summary
CVE-2024-24725 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits and 1 repository PoC.
Description
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | Through 26.0.0 | affected |
Proofs of concept
3Catalogued exploits
ExploitDBGibbon LMS < v26.0.00 - Authenticated RCEExploitDB exploitby Ali Maharramli_Fikrat Guliev_Islam RzayevNot analyzed1 file
MetasploitGibbon School Platform Authenticated PHP Deserialization VulnerabilityMetasploit exploitby Ali Maharramli +3 moreNot analyzed1 file
Repository PoCs
GitHubMelkorW/CVE-2024-24725-PoCRepository PoCby MelkorWStars: 1Not analyzed2 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-24725 exploit-db.com
https://www.exploit-db.com/exploits/51903