Glpi
by Glpi Project
Source repositories
CVEs (201)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-47760 | 0.00 | — | 0.00 | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue. | |||
| CVE-2024-47758 | 0.00 | — | 0.00 | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue. | |||
| CVE-2024-43416 | 0.00 | — | 0.01 | Nov 18, 2024 | GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address corresponds to a valid GLPI user. Version 10.0.17 fixes the issue. | |||
| CVE-2024-38370 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16. | |||
| CVE-2024-45611 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can bypass the access control policy to create a private RSS feed attached to another user account and use a… | |||
| CVE-2024-45610 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located… | |||
| CVE-2024-45609 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the… | |||
| CVE-2024-45608 | 0.00 | — | 0.01 | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17. | |||
| CVE-2024-43418 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17. | |||
| CVE-2024-43417 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Software form. Upgrade to 10.0.17. | |||
| CVE-2024-41679 | 0.00 | — | 0.01 | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17. | |||
| CVE-2024-41678 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17. | |||
| CVE-2024-40638 | 0.00 | — | 0.37 | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17. | |||
| CVE-2024-47759 | 0.00 | — | 0.00 | Nov 15, 2024 | GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17. | |||
| CVE-2024-37148 | 0.00 | — | 0.20 | Jul 10, 2024 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in some AJAX scripts to alter another user account data and take… | |||
| CVE-2024-27914 | 0.00 | — | 0.01 | Mar 18, 2024 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS… | |||
| CVE-2024-27104 | 0.00 | — | 0.01 | Mar 18, 2024 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard… | |||
| CVE-2024-27930 | 0.00 | — | 0.01 | Mar 18, 2024 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version… | |||
| CVE-2024-27756 | 0.00 | — | 0.01 | Mar 15, 2024 | GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title. | |||
| CVE-2023-51446 | 0.00 | — | 0.01 | Feb 1, 2024 | GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12. |
- CVE-2024-47760Dec 11, 2024risk 0.00cvss —epss 0.00
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.
- CVE-2024-47758Dec 11, 2024risk 0.00cvss —epss 0.00
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.
- CVE-2024-43416Nov 18, 2024risk 0.00cvss —epss 0.01
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address corresponds to a valid GLPI user. Version 10.0.17 fixes the issue.
- CVE-2024-38370Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
- CVE-2024-45611Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can bypass the access control policy to create a private RSS feed attached to another user account and use a…
- CVE-2024-45610Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located…
- CVE-2024-45609Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the…
- CVE-2024-45608Nov 15, 2024risk 0.00cvss —epss 0.01
GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.
- CVE-2024-43418Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
- CVE-2024-43417Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Software form. Upgrade to 10.0.17.
- CVE-2024-41679Nov 15, 2024risk 0.00cvss —epss 0.01
GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.
- CVE-2024-41678Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
- CVE-2024-40638Nov 15, 2024risk 0.00cvss —epss 0.37
GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.
- CVE-2024-47759Nov 15, 2024risk 0.00cvss —epss 0.00
GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.
- CVE-2024-37148Jul 10, 2024risk 0.00cvss —epss 0.20
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in some AJAX scripts to alter another user account data and take…
- CVE-2024-27914Mar 18, 2024risk 0.00cvss —epss 0.01
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS…
- CVE-2024-27104Mar 18, 2024risk 0.00cvss —epss 0.01
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard…
- CVE-2024-27930Mar 18, 2024risk 0.00cvss —epss 0.01
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version…
- CVE-2024-27756Mar 15, 2024risk 0.00cvss —epss 0.01
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
- CVE-2023-51446Feb 1, 2024risk 0.00cvss —epss 0.01
GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12.
Page 5 of 11