Vulnerability Description
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful exploitation requires Teacher or higher privileges. Exploitation could result in loss of availability of the web application.
Related Weaknesses (CWE)
References
- https://github.com/GibbonEdu/core/releases/tag/v30.0.01
- https://projectblack.io/blog/gibbon-v30-authenticated-sql-injection-and-rce/#den
FAQ
What is CVE-2026-8209?
CVE-2026-8209 is a documented vulnerability. Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the...
How severe is CVE-2026-8209?
CVSS scoring is not yet available for CVE-2026-8209. Check NVD for updates.
Is there a patch for CVE-2026-8209?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.