CVE-2020-11034
- EPSS 55.8%
- Veröffentlicht 05.05.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:38
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
CVE-2020-11035
- EPSS 0.24%
- Veröffentlicht 05.05.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:38
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.
CVE-2020-11036
- EPSS 0.79%
- Veröffentlicht 05.05.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:39
In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with content "<script>alert(1)</script>" reproduces the attac...
CVE-2020-11032
- EPSS 0.31%
- Veröffentlicht 05.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:37
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.
CVE-2013-2227
- EPSS 28.06%
- Veröffentlicht 01.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 01:51:17
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
CVE-2019-14666
- EPSS 2.85%
- Veröffentlicht 25.09.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:06
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated att...
CVE-2019-1010307
- EPSS 0.25%
- Veröffentlicht 15.07.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:09
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vect...
CVE-2019-1010310
- EPSS 0.24%
- Veröffentlicht 12.07.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:09
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is:...
CVE-2019-13240
- EPSS 0.54%
- Veröffentlicht 10.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:31
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
CVE-2019-13239
- EPSS 0.34%
- Veröffentlicht 04.07.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:31
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.