Skip to content

Insecure Direct Object Reference on ajax/comments.php

Moderate
trasher published GHSA-wq38-gwxp-8p5p Nov 25, 2020

Package

No package listed

Affected versions

<9.5.3

Patched versions

9.5.3

Description

Impact

The attack need a logged account (a self-service profile is sufficient).
You can read data from any tables of GLPI (glpi_tickets, glpi_users, etc)

Patches

e0d6a24

For more information

If you have any questions or comments about this advisory:
Email us at glpi-security@ow2.org

Severity

Moderate

CVE ID

CVE-2020-27662

Weaknesses

No CWEs

Credits