Vulnerabilities
Vulnerable Software
Glpi-Project:  >> Glpi  >> 10.0.16  Security Vulnerabilities
GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.
CVSS Score
4.8
EPSS Score
0.002
Published
2024-11-15
GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.
CVSS Score
8.1
EPSS Score
0.003
Published
2024-11-15
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
CVSS Score
6.5
EPSS Score
0.007
Published
2024-11-15


Contact Us

Shodan ® - All rights reserved