Reflected XSS Vulnerability in Gibbon Application Version 22 Allows for Arbitrary JavaScript Execution

Reflected XSS Vulnerability in Gibbon Application Version 22 Allows for Arbitrary JavaScript Execution

CVE-2021-40492 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).

Learn more about our Web Application Penetration Testing UK.