Server Side Template Injection Leads to Remote Code Execution
CVE-2024-24724
9.8CRITICAL
What is CVE-2024-24724?
A vulnerability in Gibbon, specifically in the messengerSettings.php module, permits Server Side Template Injection due to the unfiltered input passed to the Twig template engine. This flaw enables an attacker to execute arbitrary code remotely, creating significant security risks. Users are advised to implement patches to safeguard against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
39% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
