CVE-2020-15175
- EPSS 9.83%
- Veröffentlicht 07.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:00
In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becomes able to read...
CVE-2020-15176
- EPSS 0.28%
- Veröffentlicht 07.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:00
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker is able to exfiltrate sensitiv...
CVE-2020-15177
- EPSS 0.31%
- Veröffentlicht 07.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:00
In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the application and allow for vulnerabilities like Cross-Site S...
CVE-2020-15217
- EPSS 0.23%
- Veröffentlicht 07.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:06
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.
CVE-2020-11031
- EPSS 0.06%
- Veröffentlicht 23.09.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:37
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by usi...
CVE-2020-15108
- EPSS 0.34%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:04:49
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
- EPSS 7.01%
- Veröffentlicht 12.05.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:42
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, t...
CVE-2020-11062
- EPSS 0.2%
- Veröffentlicht 12.05.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:42
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.
CVE-2020-5248
- EPSS 2.84%
- Veröffentlicht 12.05.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:45
GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before inst...
CVE-2020-11033
- EPSS 0.45%
- Veröffentlicht 05.05.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:38
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalat...