CVE-2023-28632
However, it will not prevent unauthorized modification of any user emails.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can also receive sensitive data through GLPI notifications. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, account takeover can be prevented by deactivating all notifications related to `Forgotten password?` event. However, it will not prevent unauthorized modification of any user emails.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- glpi-project/glpi
- Source
- security-advisories@github.com
References
- https://github.com/glpi-project/glpi/releases/tag/10.0.7Patch, Release Notes
- https://github.com/glpi-project/glpi/releases/tag/9.5.13Patch, Release Notes
- https://github.com/glpi-project/glpi/security/advisories/GHSA-7pwm-pg76-3q9xVendor Advisory
- https://github.com/glpi-project/glpi/releases/tag/10.0.7Patch, Release Notes
- https://github.com/glpi-project/glpi/releases/tag/9.5.13Patch, Release Notes
- https://github.com/glpi-project/glpi/security/advisories/GHSA-7pwm-pg76-3q9xVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.