Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-27662
HistoryNov 26, 2020 - 5:15 p.m.

Design/Logic Flaw

2020-11-2617:15:00
PRIOn knowledge base
www.prio-n.com
7

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).

CPENameOperatorVersion
glpilt9.5.3

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%