GLPI is a free Asset and IT management...... CVE-2021-39209

6.8 AV AC AU C I A
发布: 2021-09-15
修订: 2024-11-21

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI. This issue is fixed in version 9.5.6. There are no workarounds aside from upgrading.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息