← Back to CVE List

CVE-2023-29006

Published: 2023-04-05T18:15Z
Last Modified: 2024-11-21T07:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions 2.7.7 and 2.10.1 contain a patch for this issue. As a workaround, delete the `ajax/dropdownContact.php` file from the plugin. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt