PT-2026-6105 · Glpi+1 · Glpi+1

Jpgjpgjpgjpg

·

Publicado

2026-02-04

·

Atualizado

2026-03-19

·

CVE-2026-22247

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions 11.0.0 through 11.0.4
Description A GLPI administrator can perform Server-Side Request Forgery (SSRF) requests through the Webhook feature. This allows an attacker to potentially make requests on behalf of the server, accessing internal resources or performing actions with the server's privileges.
Recommendations Update to version 11.0.5 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05698
CVE-2026-22247
GHSA-F6F6-V3QR-9P5X

Produtos afetados

Glpi
Red Os