High severity8.8NVD Advisory· Published Mar 23, 2024· Updated Jun 17, 2026
CVE-2024-24725
CVE-2024-24725
Description
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/51903nvdExploit
- gibbonedu.org/download/nvdProduct
News mentions
0No linked articles in our index yet.