CVE-2023-35939: GLPI vulnerable to unauthorized access to Dashboard data
Published Jul 5, 2023
·Updated
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat actor to interact, modify, or see Dashboard data. Version 10.0.8 contains a patch for this issue.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=9.5.0<10.0.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.8
Event History
Jul 5, 2023
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35939.
2
What is the severity of CVE-2023-35939?
The severity of CVE-2023-35939 is high with a CVSS score of 8.1.
3
What is the affected software?
The affected software is GLPI version 9.5.0 to 10.0.8.
4
What actions can a threat actor perform due to this vulnerability?
A threat actor can interact, modify, or see Dashboard data.
5
How can I fix CVE-2023-35939?
To fix CVE-2023-35939, update GLPI to version 10.0.8 or later.