VYPR
Critical severity10.0NVD Advisory· Published Nov 2, 2023· Updated Jun 17, 2026

CVE-2023-42802

CVE-2023-42802

Description

GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on /ajax and /front files to the web server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Glpi Project/Glpi3 versions
    cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: >=10.0.7,<10.0.10
    • (no CPE)range: >=10.0.7, <10.0.10
    • (no CPE)range: >= 10.0.7, < 10.0.10

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.