Server Side Template Injection Leads to Remote Code Execution
CVE-2024-24724
9.8CRITICAL
What is CVE-2024-24724?
A vulnerability in Gibbon, specifically in the messengerSettings.php module, permits Server Side Template Injection due to the unfiltered input passed to the Twig template engine. This flaw enables an attacker to execute arbitrary code remotely, creating significant security risks. Users are advised to implement patches to safeguard against potential exploitation.
