CVE-2024-24725: High severity gibbon vulnerability
Published Mar 23, 2024
·Updated
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/importrun.php&type=externalAssessment&step=4 URI.
Affected Software
2 affected components
Gibbon Gibbon<=26.0.00
GibbonEdu Gibbon<=26.0.00
Event History
Mar 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24725?
CVE-2024-24725 has been assessed as a high severity vulnerability due to its potential for remote PHP deserialization attacks.
2
How do I fix CVE-2024-24725?
To fix CVE-2024-24725, upgrade Gibbon to a version later than 26.0.00 to mitigate the vulnerability.
3
Which versions of Gibbon are affected by CVE-2024-24725?
CVE-2024-24725 affects Gibbon versions up to and including 26.0.00.
4
What type of attacks can CVE-2024-24725 allow?
CVE-2024-24725 allows authenticated users to conduct PHP deserialization attacks through specific POST requests.
5
What components of Gibbon are impacted by CVE-2024-24725?
CVE-2024-24725 impacts the modules/System Admin/import_run.php component of Gibbon.