PT-2023-6846 · Glpi+2 · Glpi+2
Jocelainesilva
·
Published
2023-09-26
·
Updated
2024-05-22
·
CVE-2023-41888
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
GLPI versions prior to 10.0.10
Description
The issue is related to the lack of path filtering on the GLPI URL, which may allow an attacker to transmit a malicious URL of the login page to attempt a phishing attack on user credentials. This can be exploited by a remote attacker to perform phishing attacks on user credentials.
Recommendations
For versions prior to 10.0.10, upgrade to version 10.0.10 to resolve the issue. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation. Avoid using unverified or suspicious URLs, especially those that may lead to the login page, until the issue is resolved.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Glpi
Red Os