cve/2024/CVE-2024-24724.md
2024-05-25 21:48:12 +02:00

704 B

CVE-2024-24724

Description

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

POC

Reference

Github

No PoCs found on GitHub currently.