CVE-2023-28632 Details
Description
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can also receive sensitive data through GLPI notifications. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, account takeover can be prevented by deactivating all notifications related to `Forgotten password?` event. However, it will not prevent unauthorized modification of any user emails.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/glpi-project/glpi/releases/tag/10.0.7 | CVE | PatchRelease Notes |
| https://github.com/glpi-project/glpi/releases/tag/9.5.13 | CVE | PatchRelease Notes |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-7pwm-pg76-3q9x | CVE | Vendor Advisory |
| https://github.com/glpi-project/glpi/releases/tag/10.0.7 | [email protected] | PatchRelease Notes |
| https://github.com/glpi-project/glpi/releases/tag/9.5.13 | [email protected] | PatchRelease Notes |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-7pwm-pg76-3q9x | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| glpi-project glpi | >= 0.83, < 9.5.13 >= 10.0.0, < 10.0.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 12, 2023 | Initial Analysis | [email protected] |