github.comConfirmation
https://github.com/glpi-project/glpi/security/advisories/GHSA-gxv6-xq9q-37hg CVE-2020-11034
MEDIUMNuclei
bypass of manageRedirect in GLPI
Record summary
CVE-2020-11034 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 9.4.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMGLPI <9.4.6 - Open RedirectCVSS 6.1
GLPI prior 9.4.6 contains an open redirect vulnerability based on a regexp.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.
Remediation
Upgrade to version 9.4.6 or later.
WeaknessesCWE-601CWE-185
Authorspikpikcu
Template tagscvecve2020redirectglpiglpi-projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
Shodan: http.title:"glpi"
Shodan: http.favicon.hash:"-1474875778"
FOFA: icon_hash="-1474875778"
FOFA: title="glpi"
Google: intitle:"glpi"
https://github.com/glpi-project/glpi/security/advisories/GHSA-gxv6-xq9q-37hg https://github.com/glpi-project/glpi/archive/9.4.6.zip https://nvd.nist.gov/vuln/detail/CVE-2020-11034 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L/
Source: ProjectDiscovery
References
3FEDORA-2020-885e2343edVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5WQMONZRWLWOXMHMYWR7A5Q5JJERPMVC FEDORA-2020-ee30e1109fVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q4BG2UTINBVV7MTJRXKBQ26GV2UINA6L