CVE-2015-7684: Critical severity glpi vulnerability
Published Oct 5, 2015
·Updated
Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a file with an executable extension as an attachment to a new ticket, then accessing it via a direct request to the file in files/tmp/.
Affected Software
1 affected component
GLPI-PROJECT GLPI<=0.85.2
Event History
Oct 5, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7684?
CVE-2015-7684 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2015-7684?
To fix CVE-2015-7684, you should update GLPI to version 0.85.3 or later.
3
Who is affected by CVE-2015-7684?
Users of GLPI versions before 0.85.3 who allow file uploads are affected by CVE-2015-7684.
4
What types of files can be exploited in CVE-2015-7684?
CVE-2015-7684 allows for the execution of arbitrary code via file uploads of executable file types.
5
Can CVE-2015-7684 be exploited remotely?
Yes, CVE-2015-7684 can be exploited remotely by authenticated users who upload malicious files.