Fields GLPI plugin vulnerable to unauthorized write access to additional fields
CVE-2023-28855

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 April 2023

What is CVE-2023-28855?

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch for this issue.

Affected Version(s)

fields < 1.13.1 < 1.13.1

fields >= 1.20.0, < 1.20.4 < 1.20.0, 1.20.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.