Headline
CVE-2022-31062
Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds b/deploy/index.php
file can be deleted if deploy feature is not used.
Unauthenticated Local File Inclusion
Package
glpiinventory (glpi)
Affected versions
<= 1.0.1
Description
Impact
A plugin public script can be used to read content of system files.
Patches
Upgrade to version 1.0.2.
Workarounds
b/deploy/index.php file can be deleted if deploy feature is not used.
Related news
GLPI Glpiinventory 1.0.1 Local File Inclusion
GLPI Glpiinventory versions 1.0.1 and below suffer from a local file inclusion vulnerability.