QID 730837

Date Published: 2023-07-17

QID 730837: Gibbon Local File Inclusion (LFI) Vulnerability

Gibbon v25.0.0 and earlier is vulnerable to a Local File Inclusion (LFI) vulnerability. A remote attacker can exploit the vulnerability and include the content of files present in the installation folder.

Affected Versions:
Gibbon v25.0.0 and earlier

Note: Qualys Threat Research Unit (TRU) found versions prior to 25.0.0 vulnerable to the LFI Vulnerability.

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to include common files like gibbon.sql to check for LFI Vulnerability.

Successful exploitation of the vulnerability may allow a remote attacker to view sensitive files leading to information disclosure.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9.4 severity.
  • Solution
    Vendor has not released patch yet. To download the latest version of Gibbon, please refer to Gibbon Download Page
    Vendor References

    CVEs related to QID 730837

    Software Advisories
    Advisory ID Software Component Link