Glpi-project

Glpi

179 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3%
  • Veröffentlicht 25.09.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:06

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated att...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 15.07.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:09

GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vect...

  • EPSS 0.24%
  • Veröffentlicht 12.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:09

GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is:...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 10.07.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:31

An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 04.07.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:31

inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.

  • EPSS 0.43%
  • Veröffentlicht 27.03.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:18:42

Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.

  • EPSS 0.28%
  • Veröffentlicht 02.07.2018 11:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:18

The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.

  • EPSS 0.81%
  • Veröffentlicht 12.03.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:12:22

A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated user to upload a file when he/s...

  • EPSS 0.33%
  • Veröffentlicht 12.03.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:12:22

An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute J...

  • EPSS 0.41%
  • Veröffentlicht 28.07.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.