Impact
On PHP 7.4 only, the LDAP server configuration form can be use to execute arbitrary code previously uploaded as a GLPI document.
Patches
Upgrade to 10.0.11.
Workarounds
Upgrade to PHP 8.x.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].
Credits
This vulnerability was discovered by Nikita Petrov (Positive Technologies).
Impact
On PHP 7.4 only, the LDAP server configuration form can be use to execute arbitrary code previously uploaded as a GLPI document.
Patches
Upgrade to 10.0.11.
Workarounds
Upgrade to PHP 8.x.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].
Credits
This vulnerability was discovered by Nikita Petrov (Positive Technologies).