CVE-2020-27663
26.11.2020, 17:15
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).Enginsight
Vendor | Product | Version |
---|---|---|
glpi-project | glpi | 𝑥 < 9.5.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration