CVE-2023-28632Improper Privilege Management in Glpi

Severity
8.1HIGHNVD
EPSS
0.3%
top 44.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 5

Description

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can also receive sensitive data through GLPI notifications. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, account takeover can be prevented by deactivating all notifications

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

NVDglpi-project/glpi0.839.5.13+1
CVEListV5glpi-project/glpi>= 0.83, < 9.5.13, >= 10.0.0, < 10.0.7+1

Patches

🔴Vulnerability Details

1
OSV
CVE-2023-28632: GLPI is a free asset and IT management software package2023-04-05