CVE-2023-45881: Gibbonedu Gibbon

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute of the bodyfile1 parameter is reflected in the response.

Affected products

  • Gibbonedu Gibbon: up to and including 25.0.00

Published 2023-11-14. Last modified 2026-06-17.