Glpi-project

Glpi

214 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.02%
  • Veröffentlicht 25.09.2026 18:38:43
  • Zuletzt bearbeitet 25.09.2026 20:17:07

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL ...

  • EPSS 0.3%
  • Veröffentlicht 25.09.2026 18:37:53
  • Zuletzt bearbeitet 30.09.2026 01:16:37

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrela...

  • EPSS 0.34%
  • Veröffentlicht 25.09.2026 18:37:10
  • Zuletzt bearbeitet 30.09.2026 01:16:37

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file ...

  • EPSS 0.57%
  • Veröffentlicht 25.09.2026 18:35:36
  • Zuletzt bearbeitet 25.09.2026 19:17:27

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST...

  • EPSS 0.39%
  • Veröffentlicht 25.09.2026 18:34:43
  • Zuletzt bearbeitet 29.09.2026 18:17:15

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers refl...

  • EPSS 0.32%
  • Veröffentlicht 25.09.2026 18:33:55
  • Zuletzt bearbeitet 25.09.2026 19:16:55

GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of an attacker-selected file hosted...

  • EPSS 0.28%
  • Veröffentlicht 25.09.2026 18:33:03
  • Zuletzt bearbeitet 29.09.2026 18:17:16

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site sc...

  • EPSS 0.36%
  • Veröffentlicht 25.09.2026 18:30:55
  • Zuletzt bearbeitet 28.09.2026 14:17:15

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credent...

  • EPSS 0.31%
  • Veröffentlicht 25.09.2026 18:29:28
  • Zuletzt bearbeitet 25.09.2026 19:17:38

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affecte...

  • EPSS 0.45%
  • Veröffentlicht 25.09.2026 18:28:25
  • Zuletzt bearbeitet 30.09.2026 01:16:37

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor authenticati...