PT-2022-11910 · Glpi · Glpi
Hansmach1Ne
·
Published
2022-01-05
·
Updated
2022-08-09
·
CVE-2021-43779
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GLPI versions prior to 2.9.1
Description
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin suffers from authenticated Remote Code Execution, allowing access to the server's underlying operating system using command injection abuse of functionality.
Recommendations
For versions prior to 2.9.1, upgrade to version 2.9.1 or later.
As a temporary workaround, consider disabling the addressing plugin until a patch is available.
Exploit
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Glpi