Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Rafaelczanett

#55226of 56,330
3.7Total CVSS
Vulnerabilities · 1
PT-2026-53103
3.7
2026-06-28
Glpi · Glpi · CVE-2026-13490
**Name of the Vulnerable Software and Affected Versions** glpi-project glpi versions 11.0.5 through 11.0.7 **Description** An authorization bypass exists in the Document Handler component within the file 'front/document.send.php'. The issue occurs in the `Document::canViewFile()` function when processing the `docid` parameter. This flaw allows a remote attacker to bypass authorization checks, although the attack is characterized by high complexity and difficult exploitability. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict access to the `docid` parameter in the 'front/document.send.php' file to minimize the risk of exploitation.