First published: Fri Jul 28 2017(Updated: )
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teclib GLPI | <=9.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11183 has a medium severity rating, indicating it can lead to significant security issues if exploited.
To fix CVE-2017-11183, upgrade GLPI to version 9.1.5 or later.
CVE-2017-11183 affects GLPI versions prior to 9.1.5, specifically allowing issues for remote authenticated administrators.
CVE-2017-11183 is a file deletion vulnerability that allows unauthorized file deletion through a crafted request.
If exploited, CVE-2017-11183 could allow attackers to delete arbitrary files on the server, potentially leading to data loss or system compromise.