GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to access (including assets, tickets, users, ...). This issue is patched in 10.0.6.
History

Mon, 10 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-10T21:20:13.945Z

Reserved: 2023-01-16T17:07:46.242Z

Link: CVE-2023-23610

cve-icon Vulnrichment

Updated: 2024-08-02T10:35:33.548Z

cve-icon NVD

Status : Modified

Published: 2023-01-26T21:18:14.223

Modified: 2024-11-21T07:46:31.737

Link: CVE-2023-23610

cve-icon Redhat

No data.