Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32299 | GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin. Using such token it is possible to negotiate a GLPI session and hijack the Super-Admin account, resulting in a Privilege Escalation. Versions 9.5.13 and 10.0.7 contain a patch for this issue. |
Mon, 10 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-10T16:36:41.599Z
Reserved: 2023-03-20T12:19:47.208Z
Link: CVE-2023-28634
Updated: 2024-08-02T13:43:23.677Z
Status : Modified
Published: 2023-04-05T17:15:07.580
Modified: 2024-11-21T07:55:42.567
Link: CVE-2023-28634
No data.
OpenCVE Enrichment
No data.
EUVD