Gibbon Authenticated SQL Injection Vulnerability

Vulnerability

An authenticated SQL injection vulnerability has been identified in Gibbon versions prior to v30.0.01. This vulnerability arises in the Tracking/graphing module, specifically within a SQL query that improperly sanitizes user input. Exploitation of this vulnerability, which requires Teacher or higher privileges, could lead to unauthorized read or write operations on the database.

Impact

Successful exploitation allows for SQL injection, which could be used to manipulate database queries, potentially leading to unauthorized data access or modification.

Reproduction

The vulnerability can be reproduced by sending a POST request to the Tracking/graphing module with crafted payloads that exploit the SQL query's input handling. The injection point is in the 'gibbonDepartmentIDs' parameter, where SQL payloads can be inserted to manipulate the query execution.

Remediation

Users are advised to update to Gibbon version v30.0.01, which addresses this vulnerability.

Added: May 9, 2026, 3:20 AM
Updated: May 9, 2026, 3:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.6
remediation
0.0
relevance
7.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.