CVE-2020-27662
26.11.2020, 17:15
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).Enginsight
Vendor | Product | Version |
---|---|---|
glpi-project | glpi | 𝑥 < 9.5.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration