All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-8208
HIGHpublished 2026-05-09 04:16 UTC · 3 months ago · modified 2026-06-17 11:03 UTC
8.9
CVSS / 10
// description
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.
// weaknesses (CWE)
- CWE-98