1 results (0.001 seconds)
CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

CVE-2024-53850 – The Addressing GLPI plugin allows data enumeration through uncontrolled object instantiation
https://notcve.org/view.php?id=CVE-2024-53850
26 Dec 2024 — The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.. Starting with 3.0.0 and before 3.0.3, a poor security check allows an unauthenticated attacker to determine whether data exists (by name) in GLPI. • https://github.com/pluginsGLPI/addressing/commit/b334187a99206abbd7d0bc84f720b0a6e69e92f0 • CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') •