Lucene search

K
freebsdFreeBSD68958E18-ED94-11ED-9688-B42E991FC52E
HistoryMar 20, 2023 - 12:00 a.m.

glpi -- multiple vulnerabilities

2023-03-2000:00:00
vuxml.freebsd.org
13
glpi project
vulnerabilities
sql injection
xss
account takeover
privilege escalation
ssrf
security

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

51.1%

glpi Project reports:

Multiple vulnerabilities found and fixed in this version:

High CVE-2023-28849: SQL injection and Stored XSS via inventory agent request.
High CVE-2023-28632: Account takeover by authenticated user.
High CVE-2023-28838: SQL injection through dynamic reports.
Moderate CVE-2023-28852: Stored XSS through dashboard administration.
Moderate CVE-2023-28636: Stored XSS on external links.
Moderate CVE-2023-28639: Reflected XSS in search pages.
Moderate CVE-2023-28634: Privilege Escalation from technician to super-admin.
Low CVE-2023-28633: Blind Server-Side Request Forgery (SSRF) in RSS feeds.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchglpi< 10.0.7,1UNKNOWN

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

51.1%

Related for 68958E18-ED94-11ED-9688-B42E991FC52E