Vulnerability record · CVE-2023-45878 · published 14 November 2023
CVE-2023-45878: Gibbon unauthenticated arbitrary file write via rubrics_visualise_saveAjax.phps
Gibbonedu · Gibbon
Gibbon 25.0.1 and earlier exposes rubrics_visualise_saveAjax.phps without authentication, accepting img, path and gibbonPersonID parameters. The img parameter is base64-decoded and written to a path built from the attacker-supplied path value and the installation directory, allowing arbitrary file creation. Because PHP files can be written, this leads to unauthenticated remote code execution.
Description
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path is used as the destination folder, concatenated with the absolute path of the installation directory. The content of the img parameter is base64 decoded and written to the defined file path. This allows creation of PHP files that permit Remote Code Execution (unauthenticated).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-accessible arbitrary file write leading to remote code execution with a CVSS of 9.8 and high EPSS.
What it is
Gibbon 25.0.1 and earlier exposes rubrics_visualise_saveAjax.phps without authentication, accepting img, path and gibbonPersonID parameters. The img parameter is base64-decoded and written to a path built from the attacker-supplied path value and the installation directory, allowing arbitrary file creation. Because PHP files can be written, this leads to unauthenticated remote code execution.
Impact
An unauthenticated attacker can write arbitrary files, including PHP, into the web-accessible installation directory and execute them, gaining remote code execution on the server.
Attack surface
Reachable over the network via the rubrics_visualise_saveAjax.phps endpoint; no authentication or user interaction is required per the CVSS vector and description.
Exploitation
Not listed in CISA KEV, but EPSS is 0.63113 (99.166th percentile) and the only references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Gibbon to a version later than 25.0.1 that fixes the unauthenticated file write.
- If upgrade is not possible, block or restrict access to rubrics_visualise_saveAjax.phps at the web server or WAF.
- Remove write permissions on the web root for the web server user so PHP files cannot be created there.
- Disable PHP execution in upload or data directories via web server configuration.
- Audit the installation directory for unexpected PHP files and remove any found.
Detection
- Monitor web logs for POST requests to rubrics_visualise_saveAjax.phps, especially with img, path and gibbonPersonID parameters.
- Alert on creation of new PHP files in the Gibbon installation directory.
- Look for base64-encoded payloads in request bodies to that endpoint.
- Check for outbound or child processes spawned by the web server user indicating code execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://herolab.usd.de/security-advisories/usd-2023-0025/ | ExploitThird Party Advisory |
| https://herolab.usd.de/security-advisories/usd-2023-0025/ | ExploitThird Party Advisory |
Track CVE-2023-45878 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-45878), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.