Back to Database
Status published
High
CVE-2022-27305
Gibbon v23 does not generate a new session ID cookie...
Vulnerability Description
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-27305
Credits & Attribution
No credits recorded in the NVD database.
More from gibbonedu
View All →CVE-2022-23871
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of...
Medium
5.4
CVE-2022-22868
Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting...
Medium
4.8
CVE-2021-40492
A reflected XSS vulnerability exists in multiple pages in version...
Medium
6.1
CVE-2021-40214
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the...
Medium
5.4
Affected Vendor
gibbonedu
View all reports →Affected Software
gibbon
Vulnerable Versions:
0
Timeline
Official Publish:
May 25th, 2022
Last Modified:
July 9th, 2026
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.