PT-2023-3282 · Glpi+1 · Fields+1
Pftpz
·
Published
2023-04-05
·
Updated
2023-06-19
·
CVE-2023-28855
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fields versions prior to 1.13.1
Fields versions prior to 1.20.4
Description
The issue is related to a lack of access control check in the Fields plugin for GLPI, allowing any authenticated user to write data to any fields container, including those to which they have no configured access. This could potentially be exploited by an attacker to record data in any container.
Recommendations
For versions prior to 1.13.1, update to version 1.13.1 or later to resolve the issue.
For versions prior to 1.20.4, update to version 1.20.4 or later to resolve the issue.
Exploit
Fix
Improper Authorization
Incorrect Authorization
SSRF
SQL injection
Improper Privilege Management
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fields
Red Os