CVE-2019-12530
CRITICALglpi_dashboard < 0.9.7 - Improper Access Control in front/sh Endpoints
Title source: llmDescription
Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.
References (1)
Core 1
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/stdonato/glpi-dashboard/commit/3a89f0085a221d7ad76d1104df6df6c634bd7f14
Scores
CVSS v3
9.8
EPSS
0.0151
EPSS Percentile
71.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (1)
glpi_dashboard_project/glpi_dashboard
< 0.9.7
Published
Jun 02, 2019
Tracked Since
Feb 18, 2026