CVE-2026-8208 PUBLISHED

Assigner: PRJBLK
Reserved: 09.05.2026 Published: 09.05.2026 Updated: 09.05.2026

Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 8.9

Product Status

Vendor gibbonedu
Product gibbon
Versions Default: affected
  • affected from 0 to 30.0.01 (excl.)

References

Problem Types

  • CWE-98 Improper control of filename for Include/Require statement in PHP program ('PHP remote file inclusion') CWE

Impacts

  • CAPEC-252 PHP Local File Inclusion