VYPR

Glpi

by Glpi Project

Source repositories

CVEs (203)

  • CVE-2023-51446MedFeb 1, 2024
    risk 0.00cvss 5.9epss 0.01

    GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12.

  • CVE-2023-46726HigDec 13, 2023
    risk 0.00cvss 7.2epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI document. Version 10.0.11 contains a patch…

  • CVE-2023-28633LowApr 5, 2023
    risk 0.00cvss 3.5epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.84 and prior to versions 9.5.13 and 10.0.7, usage of RSS feeds is subject to server-side request forgery (SSRF). In case the remote address is not a valid RSS feed, an RSS autodiscovery feature is…

  • CVE-2022-36112LowSep 14, 2022
    risk 0.00cvss 3.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or extenal calendar in planning is subject to SSRF exploit.…

  • CVE-2022-35947CriSep 14, 2022
    risk 0.00cvss 10.0epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have been found to be vulnerable to a SQL injection attack which…

  • CVE-2022-35946MedSep 14, 2022
    risk 0.00cvss 5.5epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In affected versions request input is not properly validated in the plugin…

  • CVE-2022-35945MedSep 14, 2022
    risk 0.00cvss 6.3epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Information associated to registration key are not properly escaped in registration…

  • CVE-2022-31187MedSep 14, 2022
    risk 0.00cvss 6.8epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions were found to not properly neutralize HTML tags in the global…

  • CVE-2022-31143MedSep 14, 2022
    risk 0.00cvss 5.3epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. It was found that in affected versions there is an exposure of private information…

  • CVE-2022-31068MedJun 28, 2022
    risk 0.00cvss 5.3epss 0.01

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instances with the native inventory used may leak sensitive information. The feature to get refused file is…

  • CVE-2022-24876MedJun 9, 2022
    risk 0.00cvss 5.4epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a…

  • CVE-2022-24869MedApr 21, 2022
    risk 0.00cvss 4.6epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messages with a stylesheet link. This may allow for a cross site…

  • CVE-2022-24868HigApr 21, 2022
    risk 0.00cvss 7.3epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a…

  • CVE-2022-24867HigApr 21, 2022
    risk 0.00cvss 7.5epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldap_pass is not filtered and when you look at the…

  • CVE-2022-21720MedJan 28, 2022
    risk 0.00cvss 4.9epss 0.01

    GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right…

  • CVE-2022-21719MedJan 28, 2022
    risk 0.00cvss 6.1epss 0.01

    GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.

  • CVE-2021-21324MedMar 8, 2021
    risk 0.00cvss 6.8epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 there is an Insecure Direct Object Reference (IDOR) on "Solutions". This vulnerability gives an…

  • CVE-2021-21258MedMar 2, 2021
    risk 0.00cvss 6.8epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability when using…

  • CVE-2021-21255MedMar 2, 2021
    risk 0.00cvss 5.8epss 0.01

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.

  • CVE-2020-26212HigNov 25, 2020
    risk 0.00cvss 7.7epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.3, any authenticated user has read-only permissions to…