CVE-2023-29006
HIGHGLPI Order GLPI <2.7.7-2.10.1 - Command Injection
Title source: llmDescription
The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions 2.7.7 and 2.10.1 contain a patch for this issue. As a workaround, delete the `ajax/dropdownContact.php` file from the plugin.
Scores
CVSS v3
8.8
EPSS
0.0074
EPSS Percentile
72.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
glpi-project/order
< 2.7.7
glpi-project/order
Timeline
Published
Apr 05, 2023
Tracked Since
Feb 18, 2026