PT-2023-28588 · Glpi+1 · Glpi+1

Mmnhack

·

Published

2023-10-07

·

Updated

2024-05-22

·

CVE-2023-42802

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions 10.0.7 through 10.0.9
Description GLPI is a free asset and IT management software package. An unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request.
Recommendations For versions 10.0.7 through 10.0.9, update to version 10.0.10 to fix the issue. As a temporary workaround, remove write access on /ajax and /front files to the web server.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6186
ALT-PU-2023-7633
ALT-PU-2024-8030
CVE-2023-42802
GHSA-RRH2-X4CH-PQ3M

Affected Products

Alt Linux
Glpi