CVE-2024-24725
48Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.8epss 51%
from disclosure to weapon0 days
Published on NVDMar 23
metasploitMar 18
exploitation probability
51%top 1% of all CVEs
observed exploitation
nono source reports it
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a