CVE-2023-42802: GLPI vulnerable to unallowed PHP script execution
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on /ajax and /front files to the web server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42802?
CVE-2023-42802 is a vulnerability in GLPI, a free asset and IT management software package, that allows unallowed PHP script execution.
What is the severity of CVE-2023-42802?
CVE-2023-42802 has a severity level of critical with a score of 10.
How does CVE-2023-42802 affect GLPI?
CVE-2023-42802 affects GLPI versions 10.0.7 to 10.0.10, allowing unverified object instantiation and the upload of malicious PHP files to unwanted directories.
How can I fix CVE-2023-42802?
To fix CVE-2023-42802, update your GLPI installation to version 10.0.10 or later.
Where can I find more information about CVE-2023-42802?
You can find more information about CVE-2023-42802 in the advisory on the GLPI GitHub repository and in the release notes for GLPI version 10.0.10.