Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
References
| Link | Resource |
|---|---|
| https://github.com/pluginsGLPI/fields/releases/tag/1.23.3 | Product Release Notes |
| https://github.com/pluginsGLPI/fields/security/advisories/GHSA-rj7q-mmx9-fhq7 | Vendor Advisory |
Configurations
History
18 Mar 2026, 13:57
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:teclib-edition:fields:*:*:*:*:*:glpi:*:* | |
| First Time |
Teclib-edition fields
Teclib-edition |
|
| References | () https://github.com/pluginsGLPI/fields/releases/tag/1.23.3 - Product, Release Notes | |
| References | () https://github.com/pluginsGLPI/fields/security/advisories/GHSA-rj7q-mmx9-fhq7 - Vendor Advisory |
16 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 18:16
Updated : 2026-03-18 13:57
NVD link : CVE-2026-23489
Mitre link : CVE-2026-23489
CVE.ORG link : CVE-2026-23489
JSON object : View
Products Affected
teclib-edition
- fields
CWE
CWE-20
Improper Input Validation
