First published: Mon Mar 08 2021(Updated: )
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems enabled. This is fixed in version 9.5.4.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Teclib GLPI | <9.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21326 is classified with a medium severity level due to its potential impact on user operations.
To fix CVE-2021-21326, upgrade GLPI to version 9.5.4 or later.
CVE-2021-21326 allows an attacker to create tickets for other users without proper authorization.
GLPI versions prior to 9.5.4 are affected by CVE-2021-21326.
There is no documented workaround for CVE-2021-21326; upgrading to the patched version is recommended.