PT-2023-13337 · Glpi · Glpi Cmdb Plugin
Nuri Çilengir
·
Publicado
2023-04-16
·
Atualizado
2025-02-06
·
CVE-2022-34125
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GLPI CMDB plugin versions prior to 3.0.3
Description
The issue allows attackers to gain read access to sensitive information via a
log/ pathname in the file parameter. This is achieved by exploiting the front/icon.send.php file in the CMDB plugin for GLPI.Recommendations
For versions prior to 3.0.3, update to version 3.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
front/icon.send.php file to minimize the risk of exploitation. Avoid using the log/ pathname in the file parameter until the issue is resolved.Exploit
Correção
Side Channel Attack
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Glpi Cmdb Plugin