CVE-2020-11060
Remote Code Execution in GLPI
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, the attack is only conceivable by an account having Maintenance privileges and the right to add WIFI networks. This is fixed in version 9.4.6.
En GLPI versiones anteriores a 9.4.6, un atacante puede ejecutar comandos del sistema al abusar de la funcionalidad backup. Teóricamente, esta vulnerabilidad puede ser explotada por un atacante sin una cuenta válida mediante el uso de un ataque de tipo CSRF. Debido a la dificultad de la explotación, el ataque solo es concebible por una cuenta que tenga privilegios Maintenance y el derecho de agregar redes WIFI. Esto es corregido en la versión 9.4.6.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-30 CVE Reserved
- 2020-05-12 CVE Published
- 2021-06-14 First Exploit
- 2024-01-28 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/163119/GLPI-9.4.5-Remote-Code-Execution.html | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/49992 | 2021-06-14 | |
https://www.exploit-db.com/exploits/51726 | 2023-10-09 |
URL | Date | SRC |
---|---|---|
https://github.com/glpi-project/glpi/commit/ad748d59c94da177a3ed25111c453902396f320c | 2021-11-04 | |
https://github.com/glpi-project/glpi/security/advisories/GHSA-cvvq-3fww-5v6f | 2021-11-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Glpi-project Search vendor "Glpi-project" | Glpi Search vendor "Glpi-project" for product "Glpi" | < 9.4.6 Search vendor "Glpi-project" for product "Glpi" and version " < 9.4.6" | - |
Affected
|