glpi Project reports:
Multiple vulnerabilities found and fixed in this version:
- High CVE-2023-28849: SQL injection and Stored XSS via inventory agent request.
- High CVE-2023-28632: Account takeover by authenticated user.
- High CVE-2023-28838: SQL injection through dynamic reports.
- Moderate CVE-2023-28852: Stored XSS through dashboard administration.
- Moderate CVE-2023-28636: Stored XSS on external links.
- Moderate CVE-2023-28639: Reflected XSS in search pages.
- Moderate CVE-2023-28634: Privilege Escalation from technician to super-admin.
- Low CVE-2023-28633: Blind Server-Side Request Forgery (SSRF) in RSS feeds.