CVE-2023-29006

HIGH

GLPI Order GLPI <2.7.7-2.10.1 - Command Injection

Title source: llm

Description

The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions 2.7.7 and 2.10.1 contain a patch for this issue. As a workaround, delete the `ajax/dropdownContact.php` file from the plugin.

Scores

CVSS v3 8.8
EPSS 0.0074
EPSS Percentile 72.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

glpi-project/order < 2.7.7
glpi-project/order

Timeline

Published Apr 05, 2023
Tracked Since Feb 18, 2026