Skip to content

Horizontal Privilege Escalation

Moderate
trasher published GHSA-vmj9-cg56-p7wh Mar 2, 2021

Package

glpi

Affected versions

<=9.5.3

Patched versions

None

Description

Impact

It's possible to create tickets for another user with self-service interface without delegatee systems enabled

Patches

fixed in 9.5.4

Severity

Moderate

CVE ID

CVE-2021-21326

Weaknesses

No CWEs

Credits