Vulnerabilities > CVE-2021-39190 - Missing Authorization vulnerability in Teclib-Edition System Center Configuration Manager

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
teclib-edition
CWE-862

Summary

The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.

Vulnerable Configurations

Part Description Count
Application
Teclib-Edition
1

Common Weakness Enumeration (CWE)