CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS
Percentile
51.1%
glpi Project reports:
Multiple vulnerabilities found and fixed in this version:
High CVE-2023-28849: SQL injection and Stored XSS via inventory agent request.
High CVE-2023-28632: Account takeover by authenticated user.
High CVE-2023-28838: SQL injection through dynamic reports.
Moderate CVE-2023-28852: Stored XSS through dashboard administration.
Moderate CVE-2023-28636: Stored XSS on external links.
Moderate CVE-2023-28639: Reflected XSS in search pages.
Moderate CVE-2023-28634: Privilege Escalation from technician to super-admin.
Low CVE-2023-28633: Blind Server-Side Request Forgery (SSRF) in RSS feeds.
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28632
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28634
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28636
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28639
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28838
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28849
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28852