Skip to content

Insecure Direct Object Reference on ajax/getDropdownValue.php

Moderate
trasher published GHSA-pqfv-4pvr-55r4 Nov 25, 2020

Package

No package listed

Affected versions

<9.5.3

Patched versions

9.5.3

Description

Impact

The attack need a logged account (a self-service profile is sufficient).
You can read data from any itemtype of GLPI (Ticket, Users, etc)

Data sent contains only id and name fields of the objects

Patches

e0d6a24

For more information

If you have any questions or comments about this advisory:
Email us at glpi-security@ow2.org

Severity

Moderate

CVE ID

CVE-2020-27663

Weaknesses

No CWEs

Credits