Known CVE
Gibbon LMS <= v25.0.01 - File Upload to RCE
Gibbon LMS versions 25.0.1 and earlier are vulnerable to an Arbitrary File Upload that can lead to Remote Code Execution (RCE). The issue stems from the rubrics_visualise_saveAjax.php endpoint, which, notably, does not require authentication. Because of this, unauthenticated attackers could potentially upload malicious PHP files and execute arbitrary code on the server.
CVE-2023-45878
Critical2023CVSS 9.8
cve2023 · file-upload · rce · gibbonedu · gibbon · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website