Lucene search

K

Glpi Security Vulnerabilities

cve
cve

CVE-2021-21312

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability within the document upload function (Home > Management > Documents > Add, or /front/docume...

5.4CVSS

5.8AI Score

0.001EPSS

2021-03-03 08:15 PM
27
cve
cve

CVE-2021-21313

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common.tabs.php endpoint, indeed, at least two parameters _target and id are not prope...

6.1CVSS

6.4AI Score

0.001EPSS

2021-03-03 08:15 PM
29
2
cve
cve

CVE-2021-21314

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is an XSS vulnerability involving a logged in user while updating a ticket.

5.4CVSS

5.5AI Score

0.001EPSS

2021-03-03 08:15 PM
28
4
cve
cve

CVE-2021-21324

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 there is an Insecure Direct Object Reference (IDOR) on "Solutions". This vulnerability gives an unauthorized user the abili...

6.8CVSS

6.5AI Score

0.002EPSS

2021-03-08 05:15 PM
24
cve
cve

CVE-2021-21325

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 a new budget type can be defined by user. This input is not correctly filtered. This results in a cross-site scripting atta...

6.2CVSS

5.4AI Score

0.001EPSS

2021-03-08 05:15 PM
68
cve
cve

CVE-2021-21326

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems enabled. This is fi...

7.7CVSS

6.4AI Score

0.001EPSS

2021-03-08 05:15 PM
23
cve
cve

CVE-2021-21327

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment that can be used to ca...

7.5CVSS

7.2AI Score

0.025EPSS

2021-03-08 05:15 PM
57
cve
cve

CVE-2021-3486

GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.

6.1CVSS

6AI Score

0.001EPSS

2021-05-26 10:15 PM
38
7
cve
cve

CVE-2021-39209

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI. This issue is fixed in version 9.5.6. Ther...

8.8CVSS

8.6AI Score

0.001EPSS

2021-09-15 04:15 PM
18
cve
cve

CVE-2021-39210

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue ...

6.5CVSS

6.6AI Score

0.001EPSS

2021-09-15 05:15 PM
17
cve
cve

CVE-2021-39211

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file ajax/telemetry.php, which is not needed for usual functio...

5.3CVSS

5.4AI Score

0.001EPSS

2021-09-15 05:15 PM
27
2
cve
cve

CVE-2021-39213

GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.

8.8CVSS

8.6AI Score

0.001EPSS

2021-09-15 05:15 PM
27
cve
cve

CVE-2021-44617

A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

9.8CVSS

9.9AI Score

0.002EPSS

2022-03-28 02:15 AM
58
cve
cve

CVE-2022-21719

GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.

6.1CVSS

5.9AI Score

0.001EPSS

2022-01-28 10:15 AM
46
cve
cve

CVE-2022-21720

GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the Entities update right prevents exploitation o...

4.9CVSS

6.2AI Score

0.001EPSS

2022-01-28 11:15 AM
46
cve
cve

CVE-2022-24867

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldap_pass is not filtered and when you look at the source code of the r...

7.5CVSS

7.7AI Score

0.001EPSS

2022-04-21 05:15 PM
54
cve
cve

CVE-2022-24868

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a result any user viewi...

7.3CVSS

6.1AI Score

0.001EPSS

2022-04-21 05:15 PM
48
cve
cve

CVE-2022-24869

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messages with a stylesheet link. This may allow for a cross site scripting attack vec...

5.4CVSS

6.1AI Score

0.001EPSS

2022-04-21 05:15 PM
56
cve
cve

CVE-2022-24876

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a cross site scripting ...

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-09 07:15 PM
44
5
cve
cve

CVE-2022-29250

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulnerability a user mus...

8.1CVSS

6.7AI Score

0.001EPSS

2022-06-09 08:15 PM
38
6
cve
cve

CVE-2022-31056

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and...

9.8CVSS

9.4AI Score

0.002EPSS

2022-06-28 06:15 PM
44
6
cve
cve

CVE-2022-31061

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. U...

9.8CVSS

9.6AI Score

0.002EPSS

2022-06-28 06:15 PM
56
6
cve
cve

CVE-2022-31068

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instances with the native inventory used may leak sensitive information. The feature to get refused file is not authenticated. T...

5.3CVSS

5AI Score

0.002EPSS

2022-06-28 06:15 PM
26
4
cve
cve

CVE-2022-31143

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. It was found that in affected versions there is an exposure of private information defined in setup of G...

5.3CVSS

6.1AI Score

0.001EPSS

2022-09-14 06:15 PM
21
3
cve
cve

CVE-2022-31187

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions were found to not properly neutralize HTML tags in the global search context. Users ar...

6.8CVSS

5.5AI Score

0.001EPSS

2022-09-14 06:15 PM
15
4
cve
cve

CVE-2022-35914

/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

9.8CVSS

9.6AI Score

0.974EPSS

2022-09-19 04:15 PM
779
In Wild
5
cve
cve

CVE-2022-35945

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Information associated to registration key are not properly escaped in registration key configuration pa...

6.3CVSS

6.7AI Score

0.001EPSS

2022-09-14 06:15 PM
22
3
cve
cve

CVE-2022-35946

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In affected versions request input is not properly validated in the plugin controller and can be used to...

6.5CVSS

7AI Score

0.001EPSS

2022-09-14 06:15 PM
238
4
cve
cve

CVE-2022-35947

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have been found to be vulnerable to a SQL injection attack which an attacker could lev...

10CVSS

9.8AI Score

0.002EPSS

2022-09-14 06:15 PM
236
3
cve
cve

CVE-2022-36112

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or extenal calendar in planning is subject to SSRF exploit. Server-side requests can ...

5.8CVSS

5.8AI Score

0.001EPSS

2022-09-14 06:15 PM
30
2
cve
cve

CVE-2022-39234

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user could continue to use their account as long as its cookie is valid. This issue...

8.8CVSS

8.6AI Score

0.001EPSS

2022-11-03 02:15 PM
21
6
cve
cve

CVE-2022-39262

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI administrator can define rich-text content to be displayed on login page. The displayed content is can contains malicious code that can be used to steal credentials. This issue has...

5.2CVSS

6.1AI Score

0.001EPSS

2022-11-03 02:15 PM
21
6
cve
cve

CVE-2022-39276

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or an external calendar in planning is subject to SSRF exploit. In case a remote scr...

5.3CVSS

6.3AI Score

0.001EPSS

2022-11-03 02:15 PM
27
6
cve
cve

CVE-2022-39277

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. External links are not properly sanitized and can therefore be used for a Cross-Site Scripting (XSS) at...

4.8CVSS

5.6AI Score

0.001EPSS

2022-11-03 04:15 PM
21
cve
cve

CVE-2022-39323

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been patched, please upg...

9.8CVSS

9.8AI Score

0.001EPSS

2022-11-03 03:15 PM
34
8
cve
cve

CVE-2022-39370

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Connected users may gain access to debug panel through the GLPI update script. This issue has been patc...

4.3CVSS

5.7AI Score

0.001EPSS

2022-11-03 04:15 PM
17
cve
cve

CVE-2022-39371

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Script related HTML tags in assets inventory information are not properly neutralized. This issue has b...

7.5CVSS

5.3AI Score

0.001EPSS

2022-11-03 04:15 PM
23
4
cve
cve

CVE-2022-39372

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Authenticated users may store malicious code in their account information. This issue has been patched,...

5.4CVSS

6.5AI Score

0.001EPSS

2022-11-03 04:15 PM
23
4
cve
cve

CVE-2022-39373

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Administrator may store malicious code in entity name. This issue has been patched, please upgrade to v...

4.9CVSS

5.2AI Score

0.001EPSS

2022-11-03 04:15 PM
19
4
cve
cve

CVE-2022-39375

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to create a public RSS feed to inject malicious code in dashboards of other users. Th...

5.4CVSS

6.5AI Score

0.001EPSS

2022-11-03 04:15 PM
30
2
cve
cve

CVE-2022-39376

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to inject custom fields values in mailto links. This issue has been patched, please u...

6.5CVSS

7AI Score

0.001EPSS

2022-11-03 04:15 PM
21
4
cve
cve

CVE-2022-41941

GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code in help links. This issue is patched in 10.0.6.

6.2CVSS

5.6AI Score

0.001EPSS

2023-01-26 09:16 PM
21
cve
cve

CVE-2023-22500

GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6 are vulnerable to Incorrect Authorization. This vulnerability allow unauthorized access to inventory files. Thus, if anonymous access to FAQ is allowed, inventory files are accessbile by unauthentica...

7.5CVSS

7.4AI Score

0.001EPSS

2023-01-26 09:18 PM
31
cve
cve

CVE-2023-22722

GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make actions as the vict...

6.8CVSS

6.1AI Score

0.001EPSS

2023-01-26 09:18 PM
25
cve
cve

CVE-2023-22724

GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting via malicious RSS feeds. An Administrator can import a malicious RSS feed that contains Cross Site Scripting (XSS) payloads inside RSS links. Victims who wish to visit an RSS conten...

6.2CVSS

4.8AI Score

0.001EPSS

2023-01-26 09:18 PM
27
cve
cve

CVE-2023-22725

GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cross-site Scripting. This vulnerability allow for an administrator to create a malicious external link. This issue is patched in 10.0.6.

6.2CVSS

5.5AI Score

0.001EPSS

2023-01-26 09:18 PM
20
cve
cve

CVE-2023-23610

GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to access (including a...

6.5CVSS

6.3AI Score

0.001EPSS

2023-01-26 09:18 PM
15
cve
cve

CVE-2023-28632

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user can...

8.1CVSS

7.9AI Score

0.001EPSS

2023-04-05 03:15 PM
28
cve
cve

CVE-2023-28633

GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subject to server-side request forgery (SSRF). In case the remote address is not a valid RSS feed, an RSS autodiscovery feature is triggered. This feature...

5.4CVSS

6.4AI Score

0.001EPSS

2023-04-05 04:15 PM
27
cve
cve

CVE-2023-28634

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin. Using such token it is possible to negotiate a GLPI session and hijack the Supe...

8.8CVSS

8.6AI Score

0.001EPSS

2023-04-05 05:15 PM
24
Total number of security vulnerabilities136