CVE-2019-13240
- EPSS 0.54%
- Veröffentlicht 10.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:31
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
CVE-2019-13239
- EPSS 0.34%
- Veröffentlicht 04.07.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:31
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
CVE-2019-10233
- EPSS 0.43%
- Veröffentlicht 27.03.2019 17:29:02
- Zuletzt bearbeitet 21.11.2024 04:18:42
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
CVE-2018-13049
- EPSS 0.28%
- Veröffentlicht 02.07.2018 11:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:18
The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.
CVE-2018-7562
- EPSS 1.09%
- Veröffentlicht 12.03.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:22
A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated user to upload a file when he/s...
CVE-2018-7563
- EPSS 0.28%
- Veröffentlicht 12.03.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:22
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute J...
CVE-2017-11183
- EPSS 0.41%
- Veröffentlicht 28.07.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
CVE-2017-11184
- EPSS 0.27%
- Veröffentlicht 28.07.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
CVE-2017-11474
- EPSS 0.25%
- Veröffentlicht 20.07.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.
CVE-2017-11475
- EPSS 0.23%
- Veröffentlicht 20.07.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.