CVE-2023-42802 is a critical vulnerability affecting GLPI versions 10.0.7 through 10.0.9, allowing unauthenticated attackers to upload and execute malicious PHP files. With a CVSS score of 9.8, this flaw presents a severe risk of complete compromise (confidentiality, integrity, and availability) due to its network-based attack vector and low complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating high awareness. Organizations using affected GLPI versions should immediately upgrade to 10.0.10 or implement the recommended workaround of removing write access to /ajax and /front directories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.7, < 10.0.10CPE matchmatch criteria | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.