9.1
CVE-2026-23489
- EPSS 0.12%
- Veröffentlicht 16.03.2026 17:12:43
- Zuletzt bearbeitet 18.03.2026 13:57:05
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teclib-edition ≫ Fields SwPlatformglpi Version < 1.23.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.314 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.