Skip to main content

Vendor archive

glpi-project CVEs

Beta · best-effort

205 CVEs tagged to vendor glpi-project16 Critical, 70 High, 111 Medium, 8 Low, 0 Unrated.

CVE-2021-21324

Published Mar 8, 2021

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21314

Published Mar 3, 2021

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, ther…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21313

Published Mar 3, 2021

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, ther…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21312

Published Mar 3, 2021

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, ther…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21258

Published Mar 2, 2021

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and b…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21255

Published Mar 2, 2021

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was po…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27663

Published Nov 26, 2020

In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27662

Published Nov 26, 2020

In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_ticke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26212

Published Nov 25, 2020

GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15226

Published Oct 7, 2020

In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SE…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15217

Published Oct 7, 2020

In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disab…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15177

Published Oct 7, 2020

In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced thr…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15176

Published Oct 7, 2020

In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. L…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15175

Published Oct 7, 2020

In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete th…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11031

Published Sep 23, 2020

In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15108

Published Jul 17, 2020

In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11062

Published May 12, 2020

In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11060

Published May 12, 2020

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a vali…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5248

Published May 12, 2020

GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive d…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11036

Published May 5, 2020

In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11035

Published May 5, 2020

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11034

Published May 5, 2020

In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11033

Published May 5, 2020

In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The respons…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11032

Published May 5, 2020

In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in vers…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 205 CVEsPage 7 of 9