CVE-2023-42802 CRITICAL

CVE-2023-42802: GLPI vulnerable to unallowed PHP script execution

Vendor Glpi-Project
Product glpi
Weakness CWE-20 · Input validation
Published November 2, 2023
Last update September 5, 2024

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on `/ajax` and `/front` files to the web server.

Key dates

02Disclosure timeline

November 2, 2023 CVE published
September 5, 2024 Record updated