Skip to content

Unallowed PHP script execution

Critical
orthagh published GHSA-rrh2-x4ch-pq3m Nov 2, 2023

Package

glpi (glpi)

Affected versions

>= 10.0.7

Patched versions

10.0.10

Description

Impact

An unverified object instanciation allows to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a webserver request.

Patches

Upgrade to 10.0.10.

For more information

If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.

Severity

Critical
10.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE ID

CVE-2023-42802

Weaknesses

Credits