CVE-2023-45881: XSS
GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resourcesaddQuickajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute of the bodyfile1 parameter is reflected in the response.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45881?
CVE-2023-45881 is a vulnerability in GibbonEdu Gibbon that allows for XSS through a file upload in the /modules/Planner/resources_addQuick_ajaxProcess.php.
How severe is CVE-2023-45881?
CVE-2023-45881 has a severity rating of 6.1, which is considered medium.
How does CVE-2023-45881 affect GibbonEdu Gibbon?
CVE-2023-45881 affects GibbonEdu Gibbon version 25.0.0 and earlier.
What is the CWE for CVE-2023-45881?
CVE-2023-45881 is classified under CWE-79, which is Cross-Site Scripting (XSS).
How can I fix CVE-2023-45881?
To fix CVE-2023-45881, update GibbonEdu Gibbon to version 25.0.0 or later and ensure that the imageAsLinks parameter is not set to 'Y' in /modules/Planner/resources_addQuick_ajaxProcess.php.