Skip to content

Bypassable CSRF protection

High
trasher published GHSA-5qpf-32w7-c56p Sep 15, 2021

Package

glpi (glpi)

Affected versions

< 9.5.6

Patched versions

9.5.6

Description

Impact

CSRF protection can be bypassed at many places, once user is logged into GLPI.
Malicious website is so able to perform many actions on GLPI.

Patches

Upgrade to 9.5.6

Workarounds

None.

Severity

High

CVE ID

CVE-2021-39209

Weaknesses

Credits