No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 28 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads to authorization bypass. The attack can be executed remotely. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The vendor was contacted early about this disclosure. | |
| Title | glpi-project glpi Document document.send.php canViewFile authorization | |
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Glpi-project
Glpi-project glpi |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-28T11:00:05.902Z
Reserved: 2026-06-27T15:57:41.272Z
Link: CVE-2026-13490
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-28T15:30:07Z