PT-2021-14421 · Glpi+1 · Glpi+1

Indevi0Us

·

Published

2021-03-08

·

Updated

2024-05-22

·

CVE-2021-21324

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 9.5.4
Description The issue concerns an Insecure Direct Object Reference (IDOR) on "Solutions" in GLPI. This allows an unauthorized user to enumerate GLPI items names, including users' logins, using the knowbase search form, which requires authentication. The exploitation involves modifying the item itemtype parameter in the URL of the /glpi/front/knowbaseitem.php endpoint to point to different tables, such as changing Ticket to Users, and guessing incremental IDs.
Recommendations For versions prior to 9.5.4, update to version 9.5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the knowbase search form and the /glpi/front/knowbaseitem.php endpoint to minimize the risk of exploitation. Avoid using the item itemtype and item items id parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1583
ALT-PU-2021-1660
ALT-PU-2024-8094
CVE-2021-21324
GHSA-JVWM-GQ36-3V7V

Affected Products

Alt Linux
Glpi