vendor:
GLPI Glpiinventory
by:
Nuri Çilengir
7.5
CVSS
HIGH
Unauthenticated Local File Inclusion
22
CWE
Product Name: GLPI Glpiinventory
Affected Version From: GLPI Glpiinventory <= 1.0.1
Affected Version To: GLPI Glpiinventory >= 1.0.2
Patch Exists: YES
Related CWE: CVE-2022-31062
CPE: a:glpi_project:glpiinventory:1.0.1
Platforms Tested: Ubuntu 22.04
2022
GLPI Glpiinventory v1.0.1 – Unauthenticated Local File Inclusion
The GLPI Glpiinventory plugin version 1.0.1 is vulnerable to unauthenticated local file inclusion. An attacker can exploit this vulnerability to read arbitrary files from the server.
Mitigation:
Update to the latest version of the GLPI Glpiinventory plugin (>= 1.0.2) or apply the vendor-supplied patch.