Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges. Exploitation could result in unintended read/write activities to the underlying database.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 May 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated SQL Injection in Gibbon Tracking/Graphing Module Allowing Data Read/Write | |
| First Time appeared |
Gibbonedu
Gibbonedu gibbon |
|
| Vendors & Products |
Gibbonedu
Gibbonedu gibbon |
Sat, 09 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges. Exploitation could result in unintended read/write activities to the underlying database. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PRJBLK
Published:
Updated: 2026-05-09T02:41:46.505Z
Reserved: 2026-05-09T02:33:22.106Z
Link: CVE-2026-8207
No data.
Status : Received
Published: 2026-05-09T03:16:16.227
Modified: 2026-05-09T03:16:16.227
Link: CVE-2026-8207
No data.
OpenCVE Enrichment
Updated: 2026-05-09T05:15:06Z
Weaknesses