Stored XSS Vulnerability in Gibbon Education Software by Gibbon
CVE-2021-40214

5.4MEDIUM

Key Information:

Vendor

Gibbonedu

Status
Vendor
CVE Published:
13 September 2021

What is CVE-2021-40214?

Gibbon version 22.0.00 contains a vulnerability that allows attackers to exploit the wall messages component through stored XSS, potentially injecting malicious scripts. Users interacting with the compromised component may unknowingly execute harmful code, leading to data breaches or unauthorized access. It is crucial for organizations using this version of Gibbon to promptly assess their exposure and apply necessary updates or mitigations.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.