CVE-2024-24725 is a critical PHP deserialization vulnerability affecting Gibbon through version 26.0.00, specifically impacting the import_run.php module. This flaw allows remote authenticated attackers to execute arbitrary code, leading to high impacts on confidentiality, integrity, and availability. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk. While not currently on CISA's KEV catalog or actively discussed in public forums, a Metasploit module exists, suggesting readily available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0.00CPE matchmatch criteria | cpe:2.3:a:gibbonedu:gibbon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.