CVE-2023-42462: File deletion through document upload process in GLPI
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The document upload process can be diverted to delete some files. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is GLPI?
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package.
What are the features provided by GLPI?
GLPI provides ITIL Service Desk features, licenses tracking, and software auditing.
How can the document upload process in GLPI be diverted?
The document upload process in GLPI can be diverted to delete some files.
What is the recommended action to address CVE-2023-42462?
Users are advised to upgrade to version 10 of GLPI.
What is the severity of CVE-2023-42462?
The severity of CVE-2023-42462 is critical with a CVSS score of 9.1.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-42462?
The Common Weakness Enumeration (CWE) ID for CVE-2023-42462 is CWE-434 and CWE-22.