Vulnerabilities
Vulnerable Software
Glpi-Project:  >> Glpi  >> 9.4.0  Security Vulnerabilities
In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with content "<script>alert(1)</script>" reproduces the attack. This can be exploited by a user with administrator privileges in the User-Agent field. It can also be exploited by an outside party through the following steps: 1. Create a user with the surname `" onmouseover="alert(document.cookie)` and an empty first name. 2. With this user, create a ticket 3. As an administrator (or other privileged user) open the created ticket 4. On the "last update" field, put your mouse on the name of the user 5. The XSS fires This is fixed in version 9.4.6.
CVSS Score
7.6
EPSS Score
0.008
Published
2020-05-05
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.
CVSS Score
8.8
EPSS Score
0.03
Published
2019-09-25
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
CVSS Score
5.9
EPSS Score
0.005
Published
2019-07-10
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-07-04
The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-03-29
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
CVSS Score
8.1
EPSS Score
0.004
Published
2019-03-27


Contact Us

Shodan ® - All rights reserved