CVE-2013-2225: Medium severity GLPI-PROJECT GLPI vulnerability
Published May 27, 2014
·Updated
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the predefinedfields parameter to front/ticket.form.php.
Affected Software
76 affected components
GLPI-PROJECT GLPI<=0.83.9
GLPI-PROJECT GLPI=0.5
GLPI-PROJECT GLPI=0.5-rc1
GLPI-PROJECT GLPI=0.5-rc2
GLPI-PROJECT GLPI=0.6
GLPI-PROJECT GLPI=0.6-rc1
GLPI-PROJECT GLPI=0.6-rc2
GLPI-PROJECT GLPI=0.6-rc3
GLPI-PROJECT GLPI=0.20
GLPI-PROJECT GLPI=0.21
GLPI-PROJECT GLPI=0.30
GLPI-PROJECT GLPI=0.31
GLPI-PROJECT GLPI=0.40
GLPI-PROJECT GLPI=0.41
GLPI-PROJECT GLPI=0.42
GLPI-PROJECT GLPI=0.51
GLPI-PROJECT GLPI=0.51a
GLPI-PROJECT GLPI=0.65
GLPI-PROJECT GLPI=0.65-rc1
GLPI-PROJECT GLPI=0.65-rc2
GLPI-PROJECT GLPI=0.68
GLPI-PROJECT GLPI=0.68-rc1
GLPI-PROJECT GLPI=0.68-rc2
GLPI-PROJECT GLPI=0.68-rc3
GLPI-PROJECT GLPI=0.68.1
GLPI-PROJECT GLPI=0.68.2
GLPI-PROJECT GLPI=0.68.3
GLPI-PROJECT GLPI=0.70
GLPI-PROJECT GLPI=0.70-rc1
GLPI-PROJECT GLPI=0.70-rc2
GLPI-PROJECT GLPI=0.70-rc3
GLPI-PROJECT GLPI=0.70.1
GLPI-PROJECT GLPI=0.70.2
GLPI-PROJECT GLPI=0.71
GLPI-PROJECT GLPI=0.71.1
GLPI-PROJECT GLPI=0.71.1-rc1
GLPI-PROJECT GLPI=0.71.1-rc2
GLPI-PROJECT GLPI=0.71.1-rc3
GLPI-PROJECT GLPI=0.71.2
GLPI-PROJECT GLPI=0.71.3
GLPI-PROJECT GLPI=0.71.4
GLPI-PROJECT GLPI=0.71.5
GLPI-PROJECT GLPI=0.71.6
GLPI-PROJECT GLPI=0.72
GLPI-PROJECT GLPI=0.72-rc1
GLPI-PROJECT GLPI=0.72-rc2
GLPI-PROJECT GLPI=0.72-rc3
GLPI-PROJECT GLPI=0.72.1
GLPI-PROJECT GLPI=0.72.2
GLPI-PROJECT GLPI=0.72.3
GLPI-PROJECT GLPI=0.72.4
GLPI-PROJECT GLPI=0.78
GLPI-PROJECT GLPI=0.78.1
GLPI-PROJECT GLPI=0.78.2
GLPI-PROJECT GLPI=0.78.3
GLPI-PROJECT GLPI=0.78.4
GLPI-PROJECT GLPI=0.78.5
GLPI-PROJECT GLPI=0.80
GLPI-PROJECT GLPI=0.80.1
GLPI-PROJECT GLPI=0.80.2
GLPI-PROJECT GLPI=0.80.3
GLPI-PROJECT GLPI=0.80.4
GLPI-PROJECT GLPI=0.80.5
GLPI-PROJECT GLPI=0.80.6
GLPI-PROJECT GLPI=0.80.7
GLPI-PROJECT GLPI=0.80.61
GLPI-PROJECT GLPI=0.83
GLPI-PROJECT GLPI=0.83.1
GLPI-PROJECT GLPI=0.83.2
GLPI-PROJECT GLPI=0.83.3
GLPI-PROJECT GLPI=0.83.4
GLPI-PROJECT GLPI=0.83.5
GLPI-PROJECT GLPI=0.83.6
GLPI-PROJECT GLPI=0.83.7
GLPI-PROJECT GLPI=0.83.8
GLPI-PROJECT GLPI=0.83.31
Remediation
Event History
May 27, 2014
CVE Published
02:55 PM
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2225?
CVE-2013-2225 has a severity level classified as high due to its potential for serious exploitation.
2
How do I fix CVE-2013-2225?
To fix CVE-2013-2225, upgrade to GLPI version 0.83.9 or later where the vulnerability has been patched.
3
What versions of GLPI are affected by CVE-2013-2225?
CVE-2013-2225 affects GLPI versions 0.83.9 and earlier.
4
Can CVE-2013-2225 be exploited remotely?
Yes, CVE-2013-2225 allows remote attackers to exploit the vulnerability via specific parameters.
5
What impact does CVE-2013-2225 have on GLPI?
CVE-2013-2225 can lead to remote code execution through unserialization of arbitrary PHP objects.