Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3. | |
| Title | Fields GLPI plugin vulnerable to RCE in dropdown generation | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-16T17:51:31.011Z
Reserved: 2026-01-13T15:47:41.628Z
Link: CVE-2026-23489
Updated: 2026-03-16T17:46:44.588Z
Status : Received
Published: 2026-03-16T18:16:06.800
Modified: 2026-03-16T18:16:06.800
Link: CVE-2026-23489
No data.
OpenCVE Enrichment
No data.