GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.
The vulnerability is classified as CWE-94 (Code Injection) and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine) and consists of the fact that the template mechanism in GLPI does not properly neutralize malicious input data provided by an administrator. An attacker with administrator privileges can inject specially crafted expressions into the template engine, which will be executed on the server side as code. This leads to full remote code execution (RCE) on the server hosting the application.
An attacker can gain full control over the server — read, modify or delete data, execute arbitrary code, and potentially perform lateral movement within the internal network. Due to the high impact on confidentiality, integrity and availability (C:H/I:H/A:H) and changed scope (S:C), the consequences may extend beyond the GLPI instance itself.
GLPI must be urgently updated to version 11.0.6, in which the vulnerability has been fixed. If an immediate update is not possible, it is recommended to restrict access to the administrative interface only to trusted networks and implement additional access control mechanisms (e.g., VPN, firewall).
GLPI in versions from 11.0.0 to 11.0.5 (before 11.0.6) of the Glpi-Project.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HGlpi Project Glpi
APPGlpi-Project11.0.0 – 11.0.6 (excl.)
Related vulnerabilities
PHP code injection w module htmlawed systemu GLPI
GLPI: Kradzież sesji przez nieuauthoryzowany dostęp do identyfikatorów sesji
GLPI: niezweryfikowana instancja obiektu umożliwia upload złośliwych plików PHP
SQL Injection w GLPI umożliwiający kradzież danych i zapis webshella
GLPI: SQL injection i XSS w endpoincie inwentaryzacji bez uwierzytelnienia