Glpi-project

Glpi

176 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 63.76%
  • Published 18.03.2025 18:27:54
  • Last modified 31.07.2025 18:45:03

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

  • EPSS 0.11%
  • Published 18.03.2025 18:25:13
  • Last modified 31.07.2025 18:48:57

GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.

  • EPSS 0.06%
  • Published 25.02.2025 18:15:27
  • Last modified 28.02.2025 13:35:22

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect...

  • EPSS 0.1%
  • Published 25.02.2025 18:15:27
  • Last modified 23.04.2025 18:46:00

GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php...

  • EPSS 0.07%
  • Published 25.02.2025 16:15:38
  • Last modified 04.03.2025 13:49:18

GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/updat...

Exploit
  • EPSS 0.12%
  • Published 25.02.2025 16:15:37
  • Last modified 04.03.2025 13:49:18

A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can ...

  • EPSS 0.11%
  • Published 25.02.2025 16:15:37
  • Last modified 04.03.2025 13:49:18

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some worka...

  • EPSS 0.12%
  • Published 25.02.2025 16:15:37
  • Last modified 04.03.2025 13:49:18

GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by ...

  • EPSS 0.39%
  • Published 12.12.2024 02:06:19
  • Last modified 10.01.2025 18:48:11

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for t...

  • EPSS 0.26%
  • Published 11.12.2024 17:15:17
  • Last modified 10.01.2025 19:37:41

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.