CVE-2023-28855
Summary
| CVE | CVE-2023-28855 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-05 18:15:00 UTC |
| Updated | 2023-04-12 16:38:00 UTC |
| Description | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch for this issue. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Teclib-edition | Fields | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Unauthorized write access to additionnal fields · Advisory · pluginsGLPI/fields · GitHub | MISC | github.com | |
| Release 1.20.4 · pluginsGLPI/fields · GitHub | MISC | github.com | |
| Release 1.13.1 · pluginsGLPI/fields · GitHub | MISC | github.com | |
| Merge pull request from GHSA-52vv-hm4x-8584 · pluginsGLPI/fields@784260b · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.