CVE-2024-24724

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/04/2024
Last modified:
17/07/2025

Description

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gibbonedu:gibbon:*:*:*:*:*:*:*:* 26.0.00 (including)