6.1
CVSSv3

CVE-2021-40492

Published: 03/09/2021 Updated: 07/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gibbonedu gibbon 22.0.00

Github Repositories

CVE-2021-40492 Gibbon version 22 Reflected Cross Site Scripting (XSS)

CVE-2021-40492 CVE-2021-40492 Gibbon version 22 Reflected Cross Site Scripting (XSS) Vulnerabilities cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2021-40492 A reflected Cross Site Scripting vulnerability exists in multiple pages in version 22 of the Gibbon education application that allows for arbitrary execution of JavaScript commands Vulnerable Parameters : gibbonCou