03. 10. 2026 Luca Tecchio Bug Fixes, NetEye

NetEye 4 – Security Advisory (GLPI)

Important: GLPI security update

Type/Severity

NetEye Product Security has rated this update as having a high security impact.

Topic

An update for the glpi packages is now available for NetEye 4.

Security Fix for NetEye 4.50

  • glpi-11.0.11_neteye1.25.3-1
  • glpi-autosetup-11.0.11_neteye1.25.3-1
  • glpi-configurator-11.0.11_neteye1.25.3-1
  • glpi-neteye-config-11.0.11_neteye1.25.3-1

Summary

This is the list of vulnerabilities patched in this update:

  • Authorization bypass in massive actions
  • Privilege escalation via user cloning
  • Improper rights checks in users deletion
  • SQL Injection through form actors dropdown
  • 2FA deactivation/modification on users with higher privileges
  • Reflected XSS in the dashboard search result widget
  • Users names enumaration via the planning feature
  • Missing authorization checks in the planning feature

For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section in the User Guide.

Affected Products

All NetEye 4.x versions

References

Luca Tecchio

Luca Tecchio

Software Developer - IT System & Service Management Solutions at Würth IT Italy

Author

Luca Tecchio

Software Developer - IT System & Service Management Solutions at Würth IT Italy

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive