Connected user may gain access to debug panel through the GLPI update script.
Upgrade to 10.0.4.
Delete the install/update.php script.
install/update.php
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.
Impact
Connected user may gain access to debug panel through the GLPI update script.
Patches
Upgrade to 10.0.4.
Workarounds
Delete the
install/update.phpscript.For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.