PT-2020-16342 · Teclib+1 · Glpi+1
Moderatetrasher
·
Published
2020-11-25
·
Updated
2024-05-22
·
CVE-2020-26212
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GLPI versions prior to 9.5.3
Description
The issue allows any authenticated user to have read-only permissions to the planning of every other user, including admin ones. This can be reproduced by creating a new planning, copying the CalDAV URL, and using a CalDAV client to sync the planning with the provided URL and credentials of any valid user. The same behavior happens to any group, allowing users to access planning even if they don't belong to that group.
Recommendations
For versions prior to 9.5.3, update to version 9.5.3 to resolve the issue.
As a temporary workaround, consider removing the
caldav.php file to block access to the CalDAV server.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Glpi