Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-31062

Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds b/deploy/index.php file can be deleted if deploy feature is not used.

CVE
#php#auth

Unauthenticated Local File Inclusion

Package

glpiinventory (glpi)

Affected versions

<= 1.0.1

Description

Impact

A plugin public script can be used to read content of system files.

Patches

Upgrade to version 1.0.2.

Workarounds

b/deploy/index.php file can be deleted if deploy feature is not used.

Related news

GLPI Glpiinventory 1.0.1 Local File Inclusion

GLPI Glpiinventory versions 1.0.1 and below suffer from a local file inclusion vulnerability.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907