VYPR
High severity7.2NVD Advisory· Published May 12, 2020· Updated Jun 17, 2026

CVE-2020-5248

CVE-2020-5248

Description

GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before installing GLPI. But on existing instances, data must be reencrypted with the new key. Problem is we can not know which columns or rows in the database are using that; espcially from plugins. Changing the key without updating data would lend in bad password sent from glpi; but storing them again from the UI will work.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Glpi Project/Glpi3 versions
    cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: <9.4.6
    • (no CPE)range: <9.4.6
    • (no CPE)range: < 9.4.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.