CVE-2023-28855 MEDIUM

CVE-2023-28855: Fields GLPI plugin vulnerable to unauthorized write access to additional fields

Vendor Pluginsglpi
Product fields
Weakness CWE-269
Published April 5, 2023
Last update February 10, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch for this issue.

Key dates

02Disclosure timeline

April 5, 2023 CVE published
February 10, 2025 Record updated