Описание
The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions 2.7.7 and 2.10.1 contain a patch for this issue. As a workaround, delete the ajax/dropdownContact.php file from the plugin.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.8.0 (включая) до 2.7.7 (исключая)
Одно из
cpe:2.3:a:glpi-project:order:*:*:*:*:*:glpi:*:*
cpe:2.3:a:glpi-project:order:2.10.0:*:*:*:*:glpi:*:*
EPSS
Процентиль: 72%
0.00738
Низкий
8.8 High
CVSS3
Дефекты
CWE-502
EPSS
Процентиль: 72%
0.00738
Низкий
8.8 High
CVSS3
Дефекты
CWE-502