← Vulnerability feed

Vulnerability record · CVE-2023-45878 · published 14 November 2023

CVE-2023-45878: Gibbon unauthenticated arbitrary file write via rubrics_visualise_saveAjax.phps

Gibbonedu · Gibbon

Gibbon 25.0.1 and earlier exposes rubrics_visualise_saveAjax.phps without authentication, accepting img, path and gibbonPersonID parameters. The img parameter is base64-decoded and written to a path built from the attacker-supplied path value and the installation directory, allowing arbitrary file creation. Because PHP files can be written, this leads to unauthenticated remote code execution.

9.8 CVSS 3.1 Critical EPSS 63% · top 0.8% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path is used as the destination folder, concatenated with the absolute path of the installation directory. The content of the img parameter is base64 decoded and written to the defined file path. This allows creation of PHP files that permit Remote Code Execution (unauthenticated).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated network-accessible arbitrary file write leading to remote code execution with a CVSS of 9.8 and high EPSS.

What it is

Gibbon 25.0.1 and earlier exposes rubrics_visualise_saveAjax.phps without authentication, accepting img, path and gibbonPersonID parameters. The img parameter is base64-decoded and written to a path built from the attacker-supplied path value and the installation directory, allowing arbitrary file creation. Because PHP files can be written, this leads to unauthenticated remote code execution.

Impact

An unauthenticated attacker can write arbitrary files, including PHP, into the web-accessible installation directory and execute them, gaining remote code execution on the server.

Attack surface

Reachable over the network via the rubrics_visualise_saveAjax.phps endpoint; no authentication or user interaction is required per the CVSS vector and description.

Exploitation

Not listed in CISA KEV, but EPSS is 0.63113 (99.166th percentile) and the only references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Gibbon to a version later than 25.0.1 that fixes the unauthenticated file write.
  • If upgrade is not possible, block or restrict access to rubrics_visualise_saveAjax.phps at the web server or WAF.
  • Remove write permissions on the web root for the web server user so PHP files cannot be created there.
  • Disable PHP execution in upload or data directories via web server configuration.
  • Audit the installation directory for unexpected PHP files and remove any found.

Detection

  • Monitor web logs for POST requests to rubrics_visualise_saveAjax.phps, especially with img, path and gibbonPersonID parameters.
  • Alert on creation of new PHP files in the Gibbon installation directory.
  • Look for base64-encoded payloads in request bodies to that endpoint.
  • Check for outbound or child processes spawned by the web server user indicating code execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-45878 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-24724Gibbonedu gibbon vulnerabilityGibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because i…EPSS 26%9.8CVE-2023-34598Gibbon local file inclusion via path traversalGibbon v25.0.0 is vulnerable to local file inclusion, allowing files within the installation folder to be read into the server's response. The flaw i…EPSS 47%analysed8.8CVE-2025-26211Gibbonedu gibbon cross-site request forgery vulnerabilityGibbon before 29.0.00 allows CSRF.EPSS 0.18%8.8CVE-2024-24725Gibbon PHP deserialization via columnOrder in import_run.phpGibbon through 26.0.00 passes the columnOrder POST parameter to a PHP deserialization sink in modules/System Admin/import_run.php (type=externalAsses…EPSS 51%analysed8.8CVE-2022-27305Gibbonedu gibbon vulnerabilityGibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.EPSS 0.92%7.2CVE-2023-45880Gibbonedu gibbon path traversal vulnerabilityGibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The…EPSS 1.2%6.1CVE-2024-34831Gibbonedu gibbon cross-site scripting vulnerabilitycross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the libr…EPSS 0.84%6.1CVE-2023-45881Gibbonedu gibbon cross-site scripting vulnerabilityGibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks p…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2023-45878), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.