Skip to main content

CVE-2023-46726

7.2
HIGHCVSS v3.1 Base Score
0.12%
LOW RiskEPSS (31st percentile)

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI document. Version 10.0.11 contains a patch for the issue.

Published: 12/13/2023
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.12%LOW Exploitation Risk
31st percentile

This vulnerability has a 0.12% probability of being exploited in the next 30 days, ranking higher than 31% of all scored CVEs.

Related Vulnerabilities