Vulnerabilities
Vulnerable Software
Glpi-Project:  >> Glpi  >> 0.83.3  Security Vulnerabilities
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.
CVSS Score
7.2
EPSS Score
0.003
Published
2024-12-11
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address corresponds to a valid GLPI user. Version 10.0.17 fixes the issue.
CVSS Score
7.5
EPSS Score
0.195
Published
2024-11-18
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the reports pages. Upgrade to 10.0.17.
CVSS Score
6.5
EPSS Score
0.015
Published
2024-11-15
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
CVSS Score
6.5
EPSS Score
0.018
Published
2024-11-15
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
CVSS Score
6.5
EPSS Score
0.011
Published
2024-11-15
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in the search engine to extract data from the database. This issue has been patched in version 10.0.13.
CVSS Score
7.7
EPSS Score
0.16
Published
2024-03-18
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13.
CVSS Score
6.5
EPSS Score
0.006
Published
2024-03-18
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-03-15
GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12.
CVSS Score
5.9
EPSS Score
0.006
Published
2024-02-01
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
CVSS Score
6.5
EPSS Score
0.006
Published
2024-02-01


Contact Us

Shodan ® - All rights reserved