NA

CVE-2023-42462

Published: 27/09/2023 Updated: 29/09/2023
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The document upload process can be diverted to delete some files. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project glpi

Github Repositories

GLPI PoC - Security advisory

GLPI-PoC GLPI PoC - Security advisory This repository is used to host our exploitation scripts for the vulnerabilities that have been disclosed to Teclib for the GLPI project The vulnerabilities were patched in 10010 version of GLPI CVE CVE-2023-42461 - SQL injection in ITIL actors CVE-2023-42462 - File deletion through document upload process CVE-2023-42802 - Unallowed PH