Vulnerability Description
Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glpi Dashboard Project | Glpi Dashboard | <= 0.9.7 |
Related Weaknesses (CWE)
References
- https://github.com/stdonato/glpi-dashboard/commit/3a89f0085a221d7ad76d1104df6df6PatchThird Party Advisory
- https://github.com/stdonato/glpi-dashboard/commit/3a89f0085a221d7ad76d1104df6df6PatchThird Party Advisory
FAQ
What is CVE-2019-12530?
CVE-2019-12530 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.
How severe is CVE-2019-12530?
CVE-2019-12530 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12530?
Check the references section above for vendor advisories and patch information. Affected products include: Glpi Dashboard Project Glpi Dashboard.