Описание
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.5.3 (исключая)
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 46%
0.00231
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 4.3
ubuntu
около 5 лет назад
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
CVSS3: 4.3
debian
около 5 лет назад
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct ...
EPSS
Процентиль: 46%
0.00231
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-639