← Back

CVE-2023-29006

nvd nist
Published: Apr 5, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions 2.7.7 and 2.10.1 contain a patch for this issue. As a workaround, delete the `ajax/dropdownContact.php` file from the plugin.

Affected (2)

Products: Glpi Project: Order
1 product
Order
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Glpi Project
From 1.8.0 to 2.7.7
Version 2.10.0

References (4)

Timeline

No history available yet.