Vulnerabilities
Vulnerable Software
Glpi-Project:  >> Glpi  >> 9.1.2  Security Vulnerabilities
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the reports pages. Upgrade to 10.0.17.
CVSS Score
6.5
EPSS Score
0.011
Published
2024-11-15
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
CVSS Score
6.5
EPSS Score
0.014
Published
2024-11-15
GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.
CVSS Score
8.1
EPSS Score
0.093
Published
2024-11-15
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
CVSS Score
6.5
EPSS Score
0.008
Published
2024-11-15
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in some AJAX scripts to alter another user account data and take control of it. Upgrade to 10.0.16.
CVSS Score
8.1
EPSS Score
0.068
Published
2024-07-10
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user can upload a malicious PHP script and hijack the plugin loader to execute this malicious script. Upgrade to 10.0.16.
CVSS Score
7.2
EPSS Score
0.082
Published
2024-07-10
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.
CVSS Score
4.3
EPSS Score
0.13
Published
2024-07-10
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in the search engine to extract data from the database. This issue has been patched in version 10.0.13.
CVSS Score
7.7
EPSS Score
0.164
Published
2024-03-18
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13.
CVSS Score
6.5
EPSS Score
0.005
Published
2024-03-18
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-03-15


Contact Us

Shodan ® - All rights reserved