Vulnerability record · CVE-2023-42802 · published 2 November 2023
CVE-2023-42802: Glpi-project glpi improper input validation vulnerability
Glpi Project · Glpi
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on `/ajax` and `/front` files to the web server.
Description
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on `/ajax` and `/front` files to the web server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/glpi-project/glpi/releases/tag/10.0.10 | Release Notes |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-rrh2-x4ch-pq3m | Vendor Advisory |
| https://github.com/glpi-project/glpi/releases/tag/10.0.10 | Release Notes |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-rrh2-x4ch-pq3m | Vendor Advisory |
Track CVE-2023-42802 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-42802), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.