Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-21255

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.9%
CVSS Severity
CVSS v3 Score 5.8
CVSS v2 Score 3.5
Products affected by CVE-2021-21255


Contact Us

Shodan ® - All rights reserved