Skip to content

Unauthenticated File Deletion

High
trasher published GHSA-rm52-jx9h-rwcp Oct 7, 2020

Package

glpi

Affected versions

>= 0.70

Patched versions

9.5.2

Description

​The ​pluginimage.send.php​ endpoint allows a user to specify an image from a plugin.The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory.

Impact

Any user becomes able to read all the files and folders contained in “/files/”. Some of the sensitive information that is compromised are the user sessions, logs, and more. An attacker would be able to get the Administrators session token and use that to authenticate.

Patches

TODO

For more information

If you have any questions or comments about this advisory:
Email us at glpi-security@ow2.org

Severity

High

CVE ID

CVE-2020-15175

Weaknesses

No CWEs

Credits