CVE-2023-41322
Last modified
CVE-2023-41322 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's password and then take control of their account. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's password and then take control of their account. Users are advised to upgrade to version 10.0.10. There are no known work around for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | >= 9.1.0, < 10.0.10 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-41322?
How severe is CVE-2023-41322?
How do I fix CVE-2023-41322?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-41317The Apollo Router is a configurable, high-performance graph …5.9
- CVE-2023-41318matrix-media-repo is a highly customizable multi-domain medi…5.4
- CVE-2023-41319Fides is an open-source privacy engineering platform for man…7.2
- CVE-2023-4132A use-after-free vulnerability was found in the siano smsusb…5.5
- CVE-2023-41320GLPI stands for Gestionnaire Libre de Parc Informatique is a…9.8
- CVE-2023-41321GLPI stands for Gestionnaire Libre de Parc Informatique is a…6.5
- CVE-2023-41323GLPI stands for Gestionnaire Libre de Parc Informatique is a…5.3
- CVE-2023-41324GLPI stands for Gestionnaire Libre de Parc Informatique is a…8.8
- CVE-2023-41325OP-TEE is a Trusted Execution Environment (TEE) designed as …6.7
- CVE-2023-41326GLPI stands for Gestionnaire Libre de Parc Informatique is a…8.8
- CVE-2023-41327WireMock is a tool for mocking HTTP services. WireMock can b…5.4
- CVE-2023-41328Frappe is a low code web framework written in Python and Jav…7.5
Are you affected by CVE-2023-41322?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
