First published: Tue Apr 06 2021(Updated: )
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glpi-project Dashboard | <=1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-30144.
The severity of CVE-2021-30144 is medium with a severity value of 4.3.
CVE-2021-30144 allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category in GLPI Dashboard plugin.
The affected software for CVE-2021-30144 is the GLPI Dashboard plugin version up to and including 1.0.2.
As of now, there is no fix available for CVE-2021-30144. It is recommended to keep the software up to date and apply patches when they become available.