Skip to main content

Vendor/product archive

glpi-project / glpi CVEs

Beta · best-effort

189 CVEs tagged to glpi-project / glpi14 Critical, 63 High, 104 Medium, 8 Low, 0 Unrated.

CVE-2020-11062

Published May 12, 2020

In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11060

Published May 12, 2020

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a vali…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5248

Published May 12, 2020

GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive d…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11036

Published May 5, 2020

In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11035

Published May 5, 2020

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11034

Published May 5, 2020

In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11033

Published May 5, 2020

In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The respons…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11032

Published May 5, 2020

In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in vers…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14666

Published Sep 25, 2019

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token genera…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1010307

Published Jul 15, 2019

GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on ad…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010310

Published Jul 12, 2019

GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any u…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-13240

Published Jul 10, 2019

An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13049

Published Jul 2, 2018

The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7563

Published Mar 12, 2018

An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7562

Published Mar 12, 2018

A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11184

Published Jul 28, 2017

SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11183

Published Jul 28, 2017

front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11475

Published Jul 20, 2017

GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11474

Published Jul 20, 2017

GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-7509

Published Jul 19, 2017

Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7507

Published Jul 19, 2017

Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 189 CVEsPage 7 of 8