CVE-2015-7685

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/10/2015
Last modified:
12/04/2025

Description

GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* 0.85.2 (including)