#VU74596 Improper Authorization in GLPI - CVE-2023-28634
Published: April 7, 2023
GLPI
glpi-project
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to missing authorization that allows a user with the Technician profile to view and generate a Personal token for a Super-Admin. Using such token it is possible to negotiate a GLPI session and hijack the Super-Admin account.