CVE-2026-23489

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:teclib-edition:fields:*:*:*:*:*:glpi:*:*

History

18 Mar 2026, 13:57

Type Values Removed Values Added
CPE cpe:2.3:a:teclib-edition:fields:*:*:*:*:*:glpi:*:*
First Time Teclib-edition fields
Teclib-edition
References () https://github.com/pluginsGLPI/fields/releases/tag/1.23.3 - () https://github.com/pluginsGLPI/fields/releases/tag/1.23.3 - Product, Release Notes
References () https://github.com/pluginsGLPI/fields/security/advisories/GHSA-rj7q-mmx9-fhq7 - () https://github.com/pluginsGLPI/fields/security/advisories/GHSA-rj7q-mmx9-fhq7 - Vendor Advisory

16 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 18:16

Updated : 2026-03-18 13:57


NVD link : CVE-2026-23489

Mitre link : CVE-2026-23489

CVE.ORG link : CVE-2026-23489


JSON object : View

Products Affected

teclib-edition

  • fields
CWE
CWE-20

Improper Input Validation