VYPR
Vendor

Teclib Edition

Products
4
CVEs
5
Across products
5
Status
Private

Products

4

Recent CVEs

5
  • CVE-2019-10232CriMar 27, 2019
    risk 0.02cvss 9.8epss 0.23

    Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

  • CVE-2021-39190MedSep 22, 2022
    risk 0.00cvss 5.3epss 0.00

    The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.

  • CVE-2019-12724MedJul 10, 2019
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.

  • CVE-2019-12723CriJul 10, 2019
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.

  • CVE-2019-10231CriMar 27, 2019
    risk 0.00cvss 9.8epss 0.03

    Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (inc/auth.class.php).