Gibbonedu · Gibbonedu · CVE-2026-97864
**Name of the Vulnerable Software and Affected Versions**
GibbonEdu Gibbon versions prior to 31.0.00
**Description**
In the Unit Planner component, the `makeBlock()` function within the `modules/Planner/units add blockAjax.php` file contains a flaw that allows remote attackers to bypass authentication. This is achieved by manipulating the `gibbonUnitBlockID` or `mode` arguments.
**Recommendations**
Upgrade to version 31.0.00.
As a temporary mitigation, restrict access to the `makeBlock()` function in the `modules/Planner/units add blockAjax.php` file.