Glpi-project

Glpi

184 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 27.03.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:18:42

Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.

  • EPSS 0.27%
  • Veröffentlicht 02.07.2018 11:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:18

The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.

  • EPSS 1.04%
  • Veröffentlicht 12.03.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:12:22

A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated user to upload a file when he/s...

  • EPSS 0.51%
  • Veröffentlicht 12.03.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:12:22

An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute J...

  • EPSS 0.41%
  • Veröffentlicht 28.07.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.

  • EPSS 0.21%
  • Veröffentlicht 28.07.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.

  • EPSS 0.2%
  • Veröffentlicht 20.07.2017 04:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.

  • EPSS 0.19%
  • Veröffentlicht 20.07.2017 04:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

  • EPSS 0.21%
  • Veröffentlicht 19.07.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.

  • EPSS 0.15%
  • Veröffentlicht 19.07.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket.