PT-2024-26228 · Unknown · Gibbon Core
Christian Bajada
·
Published
2024-09-08
·
Updated
2025-07-17
·
CVE-2024-34831
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gibbon Core version 26.0.00
Description
A cross-site scripting (XSS) issue allows an attacker to execute arbitrary code via the
imageLink parameter in the library manage catalog editProcess.php component. This could potentially lead to unauthorized actions on the affected system.Recommendations
For Gibbon Core version 26.0.00, consider restricting access to the
library manage catalog editProcess.php component until a patch is available, and avoid using the imageLink parameter in this component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gibbon Core