CVE-2023-28855

CVE-2023-28855

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch for this issue.

Source: CVE-2023-28855

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다