front/icon.send.php in the CMDB plugin before 3.0.3 for...
Moderate severity
Unreviewed
Published
Apr 16, 2023
to the GitHub Advisory Database
•
Updated Feb 6, 2025
Description
Published by the National Vulnerability Database
Apr 16, 2023
Published to the GitHub Advisory Database
Apr 16, 2023
Last updated
Feb 6, 2025
front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.
References