S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-34598 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in Gibbon affects v. 25.0.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-34598
9.8
CVSS

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Gibbon is an open-source school management system that helps to streamline and manage academic and administrative tasks in educational institutions. It provides a comprehensive solution to manage student records, attendance, course management, grade books, parent communication, and a lot more.

Recently, a critical vulnerability named CVE-2023-34598 has been detected in Gibbon v25.0.0. This vulnerability allows attackers to access sensitive files stored in the installation folder, leading to Local File Inclusion (LFI). As a result, attackers can execute arbitrary code, modify the database, or even take control of the server.

If the Gibbon vulnerability is exploited, attackers can gain access to confidential information such as student data, grades, and financial information. This can lead to identity theft, financial fraud, and reputational damage to the educational institution. Moreover, an attacker can leverage this vulnerability to launch other attacks, leading to data theft, ransomware attacks, and system downtime.

In conclusion, it is crucial for educational institutions using Gibbon to keep abreast of the latest vulnerabilities and implement necessary precautions to safeguard their digital assets. At s4e.io, you can leverage pro features that help you stay updated on your digital asset vulnerabilities easily and quickly. You can scan your systems continuously to get notified about any vulnerabilities and potential threats detected in your systems and networks, making it easier to harden your security posture and protect against cyber attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Regularly update the Gibbon installation to the latest version.
  • Implement a web application firewall (WAF) to filter out malicious requests.
  • Enable server-side input validation to prevent the execution of arbitrary code.
  • Encrypt sensitive data in transit and at rest to avoid data theft.
  • Limit server permissions to only authorized personnel.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.