Impact
An unverified object instanciation allows to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a webserver request.
Patches
Upgrade to 10.0.10.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.
Impact
An unverified object instanciation allows to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a webserver request.
Patches
Upgrade to 10.0.10.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.