GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://forge.glpi-project.org/issues/5218 | vendor advisory |
http://seclists.org/fulldisclosure/2015/Feb/71 | mailing list |
http://www.glpi-project.org/spip.php?page=annonce&id_breve=338 |