CVE-2014-5032 Information

Description

GLPI before 0.84.7 does not properly restrict access to cost information which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.

Reference

http://advisories.mageia.org/MGASA-2015-0017.html http://www.glpi-project.org/spip.php?page=annonce&id_breve=325 http://www.mandriva.com/security/advisories?name=MDVSA-2015:167 https://forge.indepnet.net/issues/4984

Share on: