Glpi-project

Glpi

176 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.84%
  • Published 12.05.2020 16:15:11
  • Last modified 21.11.2024 05:33:45

GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before inst...

  • EPSS 0.45%
  • Published 05.05.2020 22:15:12
  • Last modified 21.11.2024 04:56:38

In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalat...

  • EPSS 42.86%
  • Published 05.05.2020 22:15:12
  • Last modified 21.11.2024 04:56:38

In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.

  • EPSS 0.24%
  • Published 05.05.2020 22:15:12
  • Last modified 21.11.2024 04:56:38

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

Exploit
  • EPSS 0.79%
  • Published 05.05.2020 22:15:12
  • Last modified 21.11.2024 04:56:39

In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with content "<script>alert(1)</script>" reproduces the attac...

  • EPSS 0.31%
  • Published 05.05.2020 21:15:11
  • Last modified 21.11.2024 04:56:37

In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.

Exploit
  • EPSS 31.19%
  • Published 01.11.2019 17:15:10
  • Last modified 21.11.2024 01:51:17

GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

Exploit
  • EPSS 3%
  • Published 25.09.2019 20:15:10
  • Last modified 21.11.2024 04:27:06

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated att...

Exploit
  • EPSS 0.25%
  • Published 15.07.2019 18:15:12
  • Last modified 21.11.2024 04:18:09

GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vect...

  • EPSS 0.24%
  • Published 12.07.2019 18:15:11
  • Last modified 21.11.2024 04:18:09

GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is:...