RULE(RULE ID:337933)

Rule General Information
Release Date: 2024-04-16
Rule Name: Gibbon LMS Remote Command Execution Vulnerability (CVE-2024-24725)
Severity:
CVE ID:
Rule Protection Details
Description: Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:51903
https://gibbonedu.org/download/
https://cxsecurity.com/cveshow/CVE-2024-24725/
Solutions
Please contact the software vendor to update the software patch.