Improper Access Control Vulnerability
Package
deploypackage.form.php
Affected versions
< 1.4.0
Patched versions
1.5.0
Description
Hi,
Is it possible to add the PoC from my repository to the CVE?
https://github.com/geozin/CVEs/tree/main/CVE-2025-27147
Geovanni C.
…________________________________
De: GitHub Staff ***@***.***>
Enviado: terça-feira, 25 de fevereiro de 2025 11:19
Para: glpi-project/glpi-inventory-plugin ***@***.***>
Cc: Geovanni Corrêa ***@***.***>; Comment ***@***.***>
Assunto: Re: [glpi-project/glpi-inventory-plugin] Improper Access Control Vulnerability (GHSA-h6x9-jm98-cw7c)
GitHub has issued CVE-2025-27147 for this Security Advisory after reviewing it for compliance with CVE rules. Once you've published your Security Advisory, we'll publish the CVE to the CVE List<https://cve.mitre.org/cve/>.
Thank you for making the open source ecosystem more secure by fixing and responsibly disclosing this vulnerability.
—
Reply to this email directly, view it on GitHub<https://github.com/glpi-project/glpi-inventory-plugin/security/advisories/GHSA-h6x9-jm98-cw7c#advisory-comment-120715>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/ANWNSEHUUPTC55TVRRP6PRT2RR3XJAVCNFSM6AAAAABWRZSKMGVHI2DSMVQWIX3LMV45UABAKJSXA33TNF2G64TZIFSHM2LTN5ZHSQ3PNVWWK3TUHMYTEMBXGE2Q>.
You are receiving this because you are either an administrator on glpi-project/glpi-inventory-plugin, or a collaborator on GHSA-h6x9-jm98-cw7c.
|
Impact
Improper Access Control Vulnerability
Patches
Upgrade to 1.5.0.