Логотип exploitDog
bind:CVE-2023-45880
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-45880

Количество 2

Количество 2

nvd логотип

CVE-2023-45880

около 2 лет назад

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-ffw7-j6wm-254p

около 2 лет назад

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-45880

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-ffw7-j6wm-254p

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

CVSS3: 7.2
0%
Низкий
около 2 лет назад

Уязвимостей на страницу