CVE-2024-51337: XSS
Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User Admin/usermanageeditProcess.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51337?
CVE-2024-51337 is classified as a high severity Cross Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-51337?
To mitigate CVE-2024-51337, upgrade Gibbon to version 28.0.00 or later.
What type of vulnerability is CVE-2024-51337?
CVE-2024-51337 is a Cross Site Scripting (XSS) vulnerability that allows an attacker to execute scripts in the context of a user's session.
What component is affected by CVE-2024-51337?
CVE-2024-51337 affects the user management process in the Gibbon application, specifically the user_manage_editProcess.php file.
Can CVE-2024-51337 lead to data exposure?
Yes, CVE-2024-51337 can allow a remote attacker to obtain sensitive information through manipulation of the email parameter.