RULE(RULE ID:337939)

Rule General Information
Release Date: 2024-04-23
Rule Name: Gibbon LMS v26.0.00 Server-Side Template Injection Vulnerability (CVE-2024-24724)
Severity:
CVE ID:
Rule Protection Details
Description: Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:51962
https://gibbonedu.org/download/
https://packetstormsecurity.com/files/177857
https://cxsecurity.com/issue/WLB-2024040001
Solutions
Please contact the software vendor to update the software patch.