The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions 2.7.7 and 2.10.1 contain a patch for this issue. As a workaround, delete the `ajax/dropdownContact.php` file from the plugin.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-04-05 18:15
Updated : 2024-02-28 20:13
NVD link : CVE-2023-29006
Mitre link : CVE-2023-29006
CVE.ORG link : CVE-2023-29006
JSON object : View
Products Affected
glpi-project
- order
CWE
CWE-502
Deserialization of Untrusted Data