Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
glpi vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2015-7685
GLPI prior to 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.
Glpi-project Glpi
5
CVSSv2
CVE-2022-31068
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instances with the native inventory used may leak sensitive information. The feature to get refused file is n...
Glpi-project Glpi
6.8
CVSSv2
CVE-2019-10233
Teclib GLPI prior to 9.4.1.1 is affected by a timing attack associated with a cookie.
Glpi-project Glpi
4.3
CVSSv2
CVE-2022-21719
GLPI is a free asset and IT management software package. All GLPI versions before 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.
Glpi-project Glpi
NA
CVE-2023-41888
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The lack of path filtering on the GLPI URL may allow an malicious user to transmit a mali...
Glpi-project Glpi
NA
CVE-2023-36808
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one m...
Glpi-project Glpi
5.5
CVSSv2
CVE-2017-11183
front/backup.php in GLPI prior to 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
Glpi-project Glpi
7.5
CVSSv2
CVE-2017-11184
SQL injection exists in front/devicesoundcard.php in GLPI prior to 9.1.5 via the start parameter.
Glpi-project Glpi
7.5
CVSSv2
CVE-2017-11329
GLPI prior to 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
Glpi-project Glpi
6.5
CVSSv2
CVE-2017-11475
GLPI prior to 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
Glpi-project Glpi
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2024-34413
CVE-2024-34089
CVE-2024-33408
local
SQL
CVE-2024-0402
CVE-2024-33910
CVE-2024-31848
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »