CVE-2015-7685 — Glpi vulnerability
Severity
4.0MEDIUMNVD
EPSS
0.1%
top 65.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 5
Latest updateMay 17
Description
GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 8.0 | Impact: 2.9