GibbonEdu Gibbon 25.0.1 and earlier contains an unauthenticated arbitrary file-write vulnerability in the rubrics_visualise_saveAjax.phps endpoint. The endpoint accepts img, path, and gibbonPersonID parameters without requiring authentication. It base64-decodes the img value and writes it to a destination influenced by the path parameter, which is concatenated with the installation directory’s absolute path. An attacker can use this behavior to create PHP files and obtain unauthenticated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Bash script (CVE-2023-45878.sh) and a README.md. The script automates exploitation of CVE-2023-45878 in Gibbon LMS, chaining an arbitrary file write vulnerability to achieve remote code execution (RCE) on a Windows target. The process involves generating a Windows reverse shell payload using msfvenom, uploading a PHP webshell to the target via a vulnerable endpoint, using the webshell to download the reverse shell executable from the attacker's HTTP server, and finally executing the payload to obtain a reverse shell. The script requires the attacker to provide their own IP, a listening port, and the target's address. The README provides a brief overview and usage instructions. The exploit is operational and provides a working RCE chain against vulnerable Gibbon LMS instances.
This repository contains a Python exploit script (gibbonlms_cmd_shell.py) targeting CVE-2023-45878, an unauthenticated arbitrary file write vulnerability in Gibbon LMS version 25.0.1 and earlier. The exploit abuses the rubrics_visualise_saveAjax.php endpoint, which does not require authentication and allows arbitrary file writes via the 'img' and 'path' parameters. The script uploads a simple PHP webshell to the target system and provides a pseudo-interactive shell interface, allowing the user to execute arbitrary commands remotely. If the webshell is deleted, the script automatically re-uploads it and resubmits the last command. The repository is structured simply, with the main exploit logic contained in a single Python file, and includes a README with usage instructions and vulnerability details. The main fingerprintable endpoints are the vulnerable PHP endpoint and the location of the uploaded webshell.
This repository contains a Python exploit script (CVE-2023-45878.py) and a README.md. The exploit targets CVE-2023-45878, an unauthenticated arbitrary file upload vulnerability in Gibbon CMS (versions 25.0.1 and before). The main script automates the exploitation process by uploading a PHP webshell to the vulnerable endpoint ('modules/Rubrics/rubrics_visualise_saveAjax.php') using a specially crafted POST request. The payload is a base64-encoded PHP script that allows remote command execution via HTTP GET requests. The script supports verifying the presence of the shell, entering an interactive shell mode (with features like file upload/download and directory navigation), and customizing the shell filename and verification tag. The exploit is operational and provides a functional webshell for post-exploitation activities. The repository is well-structured, with clear documentation and usage instructions in the README.md. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
This repository contains a Python exploit script (CVE-2023-45878.py) and a README.md. The exploit targets CVE-2023-45878, an arbitrary file write vulnerability in GibbonEdu's rubrics_visualise_saveAjax.php endpoint. The script allows an unauthenticated attacker to upload a PHP web shell to the server and then either execute arbitrary system commands or trigger a PowerShell reverse shell for remote access. The main attack vector is network-based, exploiting an HTTP POST request to the vulnerable endpoint. The script is operational, providing a working payload and clear usage instructions. The README.md provides background, usage examples, and a disclaimer. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
This repository contains a Go-based exploit for CVE-2023-45878, targeting GibbonEdu Gibbon version 25.0.1 and earlier, specifically on Windows Server. The exploit leverages an arbitrary file write vulnerability in the '/modules/Rubrics/rubrics_visualise_saveAjax.php' endpoint to upload a web shell ('shell.php') to the target server. It then generates a PowerShell reverse shell payload ('shell.ps1'), serves it via a local HTTP server on port 8000, and instructs the web shell to download and execute this payload, resulting in a reverse shell connection back to the attacker's machine. The repository consists of a single main exploit file ('gibbon-rce-exploit.go'), a Go module file, a README with usage instructions, and a VSCode launch configuration. The exploit is operational and provides remote command execution on vulnerable Windows servers. No hardcoded IPs or domains are present; all endpoints are constructed from user-supplied arguments.
This repository contains a Python exploit script (CVE-2023-45878.py) targeting GibbonEdu Gibbon version 25.0.1 (CVE-2023-45878). The exploit abuses the 'modules/Rubrics/rubrics_visualise_saveAjax.php' endpoint to perform an arbitrary file write, uploading a PHP webshell to the server. The script then accesses the uploaded webshell and executes a system command ('whoami') via the 'cmd' GET parameter, demonstrating remote code execution. The repository includes a README and a .gitignore, with the main exploit logic contained in the Python script. The exploit is operational, providing a working webshell payload, and requires the attacker to supply the target Gibbon URL as an argument.
This repository provides a functional exploit for CVE-2023-45878, targeting Gibbon LMS running on XAMPP for Windows. The main exploit script (CVE-2023-45878.py) is written in Python and automates the process of uploading a PHP webshell to the target via a vulnerable endpoint (/modules/Rubrics/rubrics_visualise_saveAjax.php). Once the webshell (shell.php) is uploaded, the script can execute arbitrary commands on the target or facilitate a reverse shell by hosting a PowerShell script (shell.ps1) and instructing the target to download and execute it. The exploit supports both single command execution and full reverse shell access. The repository also includes a README with usage instructions and a GitHub Actions workflow for Python package testing. The exploit is operational, providing real remote code execution capabilities, and exposes several fingerprintable endpoints related to the attack process.
This repository contains a Python exploit script (CVE-2023-45878.py) and a README.md. The exploit targets Gibbon LMS version 25.0.1, leveraging an arbitrary file write vulnerability (CVE-2023-45878) in the '/modules/Rubrics/rubrics_visualise_saveAjax.php' endpoint. The script uploads a base64-encoded PHP web shell to the target server, then uses this shell to execute a PowerShell reverse shell payload, connecting back to the attacker's specified IP and port. The attacker must provide the target URL, their own IP and port, and optionally a filename for the uploaded shell. The README provides usage instructions and context. The exploit is operational, providing a working reverse shell if the target is vulnerable. No detection or fake code is present; the script is a functional exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.