Skip to content

Remote Code Execution (RCE) via the backup functionality.

High
orthagh published GHSA-cvvq-3fww-5v6f May 11, 2020

Package

glpi-project/glpi

Affected versions

0.85

Patched versions

9.4.6

Description

Impact

An attacker can execute system commands by abusing the backup functionality.

Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF.

Due to the difficulty of the exploitation for an attacker without a valid account, the attack is only conceivable by an account having Maintenance privileges and the right to add WIFI networks.

Patches

ad748d5

Workarounds

Delete the front/backup.php file.

Versions affected

Details are in the reference below.

Reference

https://offsec.almond.consulting/playing-with-gzip-rce-in-glpi.html

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2020-11060

Weaknesses

No CWEs