vendor:
GLPI
by:
Vadym Soroka
7.5
CVSS
HIGH
Unsafe Reflection
470
CWE
Product Name: GLPI
Affected Version From: <=9.5.3
Affected Version To: <=9.5.3
Patch Exists: NO
Related CWE: CVE-2021-21327
CPE: a:glpi_project:glpi:9.5.3
Platforms Tested:
2021
GLPI 9.5.3 – ‘fromtype’ Unsafe Reflection
Non-authenticated user can remotely instantiate object of any class existing in the GLPI environment that can be used to carry out malicious attacks, or to start a “POP chain”. As an example of direct impact, this vulnerability affects integrity of the GLPI core platform and third-party plugins runtime misusing classes which implement some sensitive operations in their constructors or destructors.
Mitigation:
Update to GLPI version >9.5.3 or apply the patch provided by the vendor