Vulnerability Details CVE-2023-35939
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat actor to interact, modify, or see Dashboard data. Version 10.0.8 contains a patch for this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.2%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2023-35939
-
cpe:2.3:a:glpi-project:glpi:10.0.0
-
cpe:2.3:a:glpi-project:glpi:10.0.1
-
cpe:2.3:a:glpi-project:glpi:10.0.2
-
cpe:2.3:a:glpi-project:glpi:10.0.3
-
cpe:2.3:a:glpi-project:glpi:10.0.4
-
cpe:2.3:a:glpi-project:glpi:10.0.5
-
cpe:2.3:a:glpi-project:glpi:10.0.6
-
cpe:2.3:a:glpi-project:glpi:10.0.7
-
cpe:2.3:a:glpi-project:glpi:9.5.0
-
cpe:2.3:a:glpi-project:glpi:9.5.1
-
cpe:2.3:a:glpi-project:glpi:9.5.10
-
cpe:2.3:a:glpi-project:glpi:9.5.11
-
cpe:2.3:a:glpi-project:glpi:9.5.12
-
cpe:2.3:a:glpi-project:glpi:9.5.13
-
cpe:2.3:a:glpi-project:glpi:9.5.2
-
cpe:2.3:a:glpi-project:glpi:9.5.3
-
cpe:2.3:a:glpi-project:glpi:9.5.4
-
cpe:2.3:a:glpi-project:glpi:9.5.5
-
cpe:2.3:a:glpi-project:glpi:9.5.6
-
cpe:2.3:a:glpi-project:glpi:9.5.7
-
cpe:2.3:a:glpi-project:glpi:9.5.8
-
cpe:2.3:a:glpi-project:glpi:9.5.9