CVE-2023-35940: GLPI vulnerable to unauthenticated access to Dashboard data
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.8
Event History
Frequently Asked Questions
What is CVE-2023-35940?
CVE-2023-35940 is a vulnerability in the GLPI software that allows an unauthenticated user to access dashboards data.
What is the severity of CVE-2023-35940?
The severity of CVE-2023-35940 is high with a score of 7.5.
What version of GLPI is affected by CVE-2023-35940?
GLPI versions prior to 10.0.8, starting from version 9.5.0, are affected by CVE-2023-35940.
How to fix CVE-2023-35940?
To fix CVE-2023-35940, update GLPI to version 10.0.8 or later.
Where can I find more information about CVE-2023-35940?
More information about CVE-2023-35940 can be found at the following references:<br>- [GLPI-Project Releases](https://github.com/glpi-project/glpi/releases/tag/10.0.8)<br>- [GLPI-Project Security Advisories](https://github.com/glpi-project/glpi/security/advisories/GHSA-qrh8-rg45-45fw)