CVE-2023-42802

    Dashboard / Vulnerabilities / CVE-2023-42802

    CVE-2023-42802

    Published: 2 Nov 2023Last Modified: 12 Aug 2026

    Summary: GLPI vulnerable to unallowed PHP script execution

    Details: GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on `/ajax` and `/front` files to the web server.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- bce21331d50a020cd0928178a68fe4aac2cc50b4

    Affected versions

    10.0.9
    10.0.8
    10.0.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-42802 | CVE-DB