CVE-2023-46726: GLPI Remote code execution from LDAP server configuration form on PHP 7.4
Published Dec 13, 2023
·Updated
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI document. Version 10.0.11 contains a patch for the issue.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=10.0.0<10.0.11
Remediation
Event History
Dec 13, 2023
CVE Published
06:25 PM
Data Sourced
06:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46726?
CVE-2023-46726 has been reported with a high severity rating due to its potential for executing arbitrary code.
2
How do I fix CVE-2023-46726?
To fix CVE-2023-46726, update your GLPI installation to version 10.0.11 or later.
3
What versions of GLPI are affected by CVE-2023-46726?
CVE-2023-46726 affects GLPI versions starting from 10.0.0 up to but not including 10.0.11.
4
What specific configuration does CVE-2023-46726 exploit?
CVE-2023-46726 exploits the LDAP server configuration form in GLPI.
5
What version of PHP is affected by CVE-2023-46726?
CVE-2023-46726 specifically impacts GLPI running on PHP version 7.4.