Skip to content

Add authentication/LDAP/SSO bypass modules#16

Open
UncleJ4ck wants to merge 1 commit into
Orange-Cyberdefense:mainfrom
UncleJ4ck:glpi-auth-bypass-modules
Open

Add authentication/LDAP/SSO bypass modules#16
UncleJ4ck wants to merge 1 commit into
Orange-Cyberdefense:mainfrom
UncleJ4ck:glpi-auth-bypass-modules

Conversation

@UncleJ4ck

@UncleJ4ck UncleJ4ck commented Jun 17, 2026

Copy link
Copy Markdown

Authentication-flow modules split out of #12: LDAP filter injection in the login path, SSO identity swap, MFA accessibility bypass, and the LDAP import-search vector.

Notes:

  • Split from Add behaviorally-validated GLPI CVE/GHSA detection modules #12, one PR per vulnerability class.
  • Uses the existing self.get/self.post helpers (CSRF + URL expansion); a few apirest and edge calls stay direct where the helper would add nothing.
  • Exercised against live 10.0.x/11.0.x vulnerable and patched instances.

@UncleJ4ck UncleJ4ck force-pushed the glpi-auth-bypass-modules branch from 7c01eec to ed89050 Compare June 17, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant