Количество 8
Количество 8
CVE-2023-28632
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can also receive sensitive data through GLPI notifications. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, account takeover can be prevented by deactivating all notifications related to `Forgotten password?` event. However, it will not prevent unauthorized modification of any user emails.
CVE-2023-28632
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can also receive sensitive data through GLPI notifications. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, account takeover can be prevented by deactivating all notifications related to `Forgotten password?` event. However, it will not prevent unauthorized modification of any user emails.
CVE-2023-28632
GLPI is a free asset and IT management software package. Starting in v ...
BDU:2023-03381
Уязвимость системы работы с заявками и инцидентами GLPI, связанная с неправильным управлением привилегиями, позволяющая нарушителю повышать привилегии внутри приложения
ALT-PU-2023-1932
ALT-PU-2023-1932: package `glpi` update to version 9.5.13-alt1
ALT-PU-2023-1801
ALT-PU-2023-1801: package `glpi` update to version 10.0.7-alt1
ROS-20230619-01
Множественные уязвимости GLPI
ALT-PU-2023-7633
ALT-PU-2023-7633: package `glpi` update to version 10.0.10-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-28632 GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can also receive sensitive data through GLPI notifications. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, account takeover can be prevented by deactivating all notifications related to `Forgotten password?` event. However, it will not prevent unauthorized modification of any user emails. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
CVE-2023-28632 GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can also receive sensitive data through GLPI notifications. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, account takeover can be prevented by deactivating all notifications related to `Forgotten password?` event. However, it will not prevent unauthorized modification of any user emails. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
CVE-2023-28632 GLPI is a free asset and IT management software package. Starting in v ... | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
BDU:2023-03381 Уязвимость системы работы с заявками и инцидентами GLPI, связанная с неправильным управлением привилегиями, позволяющая нарушителю повышать привилегии внутри приложения | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
ALT-PU-2023-1932 ALT-PU-2023-1932: package `glpi` update to version 9.5.13-alt1 | CVSS3: 8.8 | больше 3 лет назад | ||
ALT-PU-2023-1801 ALT-PU-2023-1801: package `glpi` update to version 10.0.7-alt1 | CVSS3: 10 | больше 3 лет назад | ||
ROS-20230619-01 Множественные уязвимости GLPI | CVSS3: 10 | больше 3 лет назад | ||
ALT-PU-2023-7633 ALT-PU-2023-7633: package `glpi` update to version 10.0.10-alt1 | CVSS3: 10 | почти 3 года назад |
Уязвимостей на страницу