VYPR

Glpi

by Glpi Project

Source repositories

CVEs (203)

  • CVE-2022-35914CriKEVSep 19, 2022
    risk 0.87cvss 9.8epss 1.00

    /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

  • CVE-2022-31056CriJun 28, 2022
    risk 0.67cvss 9.8epss 0.09

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved…

  • CVE-2023-42802CriNov 2, 2023
    risk 0.65cvss 10.0epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system…

  • CVE-2023-28849CriApr 5, 2023
    risk 0.65cvss 10.0epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default,…

  • CVE-2025-21619CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.

  • CVE-2024-31705CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

  • CVE-2021-44617CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

  • CVE-2017-11184CriJul 28, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.

  • CVE-2017-11474CriJul 20, 2017
    risk 0.64cvss 9.8epss 0.01

    GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.

  • CVE-2017-11329CriJul 17, 2017
    risk 0.64cvss 9.8epss 0.01

    GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.

  • CVE-2023-28838CriApr 5, 2023
    risk 0.62cvss 9.6epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell…

  • CVE-2023-35924HigJul 5, 2023
    risk 0.60cvss 8.6epss 0.51

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for…

  • CVE-2025-24799HigMar 18, 2025
    risk 0.59cvss 7.5epss 0.86

    GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

  • CVE-2023-36808HigJul 5, 2023
    risk 0.59cvss 8.6epss 0.48

    GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one…

  • CVE-2025-24801HigMar 18, 2025
    risk 0.57cvss 8.5epss 0.20

    GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.

  • CVE-2024-47760HigDec 11, 2024
    risk 0.57cvss 8.8epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2024-47758HigDec 11, 2024
    risk 0.57cvss 8.8epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2024-27756HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.01

    GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

  • CVE-2023-28634HigApr 5, 2023
    risk 0.57cvss 8.8epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin. Using such token it is possible to negotiate a GLPI session…

  • CVE-2021-39209HigSep 15, 2021
    risk 0.57cvss 8.8epss 0.01

    GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI. This issue is fixed in…

Page 1 of 11