CVE-2023-46726

HIGH

GLPI <10.0.11 - RCE

Title source: llm
STIX 2.1

Description

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI document. Version 10.0.11 contains a patch for the issue.

Scores

CVSS v3 7.2
EPSS 0.0012
EPSS Percentile 30.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
glpi-project/glpi 10.0.0 - 10.0.11
Published Dec 13, 2023
Tracked Since Feb 18, 2026