Cross-Site Scripting Vulnerability in Gibbon Core Software
CVE-2024-34831

Currently unrated

Key Information:

Vendor
Gibbon
Vendor
CVE Published:
10 September 2024

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

Summary

A cross-site scripting (XSS) vulnerability exists in Gibbon Core version 26.0.00 that may allow attackers to execute arbitrary code. This flaw is triggered through the manipulation of the imageLink parameter within the library_manage_catalog_editProcess.php component. If exploited, it can lead to unauthorized actions and data exposure, posing significant security risks to users of the affected version.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • Vulnerability published

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability Reserved

.