CVE-2018-7562

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-7562
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7562.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-7562
Related
Published
2018-03-12T21:29:01Z
Modified
2025-01-14T07:40:55.026086Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated user to upload a file when he/she creates a new ticket via front/fileupload.php. This feature is protected using different types of security features like the check on the file's extension. However, the application uploads and creates a file, though this file is not allowed, and then deletes the file in the uploadFiles method in inc/glpiuploaderhandler.class.php.

References

Affected packages

Git / github.com/glpi-project/glpi

Affected ranges

Type
GIT
Repo
https://github.com/glpi-project/glpi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.90
0.90-RC1
0.90-RC2
0.90-beta1
0.90-beta2
0.90.1

9.*

9.1
9.1-RC1
9.1-RC2
9.2
9.2-RC1
9.2-RC2
9.2.1