Skip to content

Known CVE

Gibbon LMS <= v25.0.01 - File Upload to RCE

Gibbon LMS versions 25.0.1 and earlier are vulnerable to an Arbitrary File Upload that can lead to Remote Code Execution (RCE). The issue stems from the rubrics_visualise_saveAjax.php endpoint, which, notably, does not require authentication. Because of this, unauthenticated attackers could potentially upload malicious PHP files and execute arbitrary code on the server.

CVE-2023-45878

Critical2023CVSS 9.8

cve2023 · file-upload · rce · gibbonedu · gibbon · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website