PT-2024-34601 · Gibbon · Gibbon

Aziz0X48

·

Published

2024-11-21

·

Updated

2025-07-17

·

CVE-2024-51337

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Gibbon versions prior to 28.0.00
Description The issue allows a remote attacker to obtain sensitive information via the email parameter found in the "/Gibbon/modules/User Admin/user manage editProcess.php" API endpoint.
Recommendations For versions prior to 28.0.00, update to version 28.0.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/Gibbon/modules/User Admin/user manage editProcess.php" endpoint or avoiding the use of the email parameter until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51337

Affected Products

Gibbon