VulnerabilityModified
CVE-2023-28855
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms.
MEDIUM 6.5EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch for this issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- teclib-edition/fields
- Source
- security-advisories@github.com
References
- https://github.com/pluginsGLPI/fields/commit/784260be7db185bb1e7d66b299997238c4c0205dPatch
- https://github.com/pluginsGLPI/fields/releases/tag/1.13.1Release Notes
- https://github.com/pluginsGLPI/fields/releases/tag/1.20.4Release Notes
- https://github.com/pluginsGLPI/fields/security/advisories/GHSA-52vv-hm4x-8584Vendor Advisory
- https://github.com/pluginsGLPI/fields/commit/784260be7db185bb1e7d66b299997238c4c0205dPatch
- https://github.com/pluginsGLPI/fields/releases/tag/1.13.1Release Notes
- https://github.com/pluginsGLPI/fields/releases/tag/1.20.4Release Notes
- https://github.com/pluginsGLPI/fields/security/advisories/GHSA-52vv-hm4x-8584Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.