Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Gibbon v30.0.00: Authenticated SQL Injection and RCE

Summary

Security research on Gibbon, an open-source school management platform: Teacher-level users and above could exploit SQL injection, LFI leading to RCE, and DoS. Fixed in v30.0.01.
Published
Collected

original ↗

Related coverage

back