GLPI vulnerable to unallowed PHP script execution
CVE-2023-42802
What is CVE-2023-42802?
GLPI, a widely-used free asset and IT management software, has a vulnerability that allows an attacker to exploit unverified object instantiation. This flaw, present in versions 10.0.7 to 10.0.9, enables the upload of malicious PHP files to unintended directories, which may lead to the execution of these files via web server requests, depending on the server configuration and available libraries. Users are advised to upgrade to version 10.0.10, which addresses this issue. As an immediate mitigation, it is recommended to remove write access on the /ajax and /front directories for the web server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
glpi >= 10.0.7, < 10.0.10
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
