CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.2. See the original NVD description below for full technical details.
CVE
CVE-2023-45880
Severity
HIGH
CVSS
7.2
EPSS
1.21%
Original NVD Description
GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.
Related CVEs
Other vulnerabilities affecting the same vendor(s)