Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability in GLPI IT management software allows a malicious actor with administrator privileges to upload a crafted file, potentially leading to the remote execution of scripts on the server. The primary concern is to confirm if your organization utilizes this software and if it is exposed to unauthorized access.
- Admins can run malicious code.
- Confirm if GLPI is in use.
- Assess potential exposure and risk.
Attack Path
How an attacker could exploit the issue
An attacker with administrator privileges could exploit this vulnerability by crafting a malicious file containing an illustration or scene identifier. When this file is imported using the Form import feature, it can write an executable file to a server location outside the designated directory. This allows an attacker to remotely execute malicious scripts on the server.
- Requires administrator access.
- Exploited through crafted file import.
- Risk of remote script execution.
Live Threat
Current exploitation, exposure, and threat context
A form administrator could upload a malicious illustration or scene identifier that, when imported, is written to an executable server location. This could allow an attacker to remotely execute malicious scripts on the server.
- Server-side scripts could be executed.
- Malicious files could be uploaded to the server.
- Remote code execution on the server.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for IT asset management, application ownership, and infrastructure hosting should coordinate to address this vulnerability. The initial focus should be on discovering all instances of the affected software, verifying their exposure and business criticality, and identifying the specific application owner for each deployment. This will enable a prioritized remediation plan to mitigate risk.
- Own Issue: IT Asset Management and Application Owners.
- Verify First: Identify all GLPI instances and exposure.
- Action Follows: Plan and coordinate targeted remediation.