GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to access (including assets, tickets, users, ...). This issue is patched in 10.0.6.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-01-25T05:46:35.549Z

Updated:

Reserved: 2023-01-16T17:07:46.242Z


Link: CVE-2023-23610

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-01-26T21:18:14.223

Modified: 2023-02-02T18:33:18.300


Link: CVE-2023-23610

JSON object: View

cve-icon Redhat Information

No data.