PT-2020-16342 · Teclib+1 · Glpi+1

Moderatetrasher

·

Published

2020-11-25

·

Updated

2024-05-22

·

CVE-2020-26212

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 9.5.3
Description The issue allows any authenticated user to have read-only permissions to the planning of every other user, including admin ones. This can be reproduced by creating a new planning, copying the CalDAV URL, and using a CalDAV client to sync the planning with the provided URL and credentials of any valid user. The same behavior happens to any group, allowing users to access planning even if they don't belong to that group.
Recommendations For versions prior to 9.5.3, update to version 9.5.3 to resolve the issue. As a temporary workaround, consider removing the caldav.php file to block access to the CalDAV server.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3557
ALT-PU-2020-3558
ALT-PU-2024-8094
CVE-2020-26212
GHSA-QMW3-87HR-5WGX

Affected Products

Alt Linux
Glpi