CVE-2023-45880

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.
References
Link Resource
https://herolab.usd.de/security-advisories/usd-2023-0022/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gibbonedu:gibbon:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-11-14 06:15

Updated : 2023-11-17 18:13


NVD link : CVE-2023-45880

Mitre link : CVE-2023-45880

CVE.ORG link : CVE-2023-45880


JSON object : View

Products Affected

gibbonedu

  • gibbon
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')