CVE-2021-39213Injection in Glpi

CWE-74Injection2 documents2 sources
Severity
8.8HIGHNVD
EPSS
0.4%
top 42.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 15

Description

GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDglpi-project/glpi9.19.5.6
CVEListV5glpi-project/glpi>= 9.1, < 9.5.6

🔴Vulnerability Details

1
OSV
CVE-2021-39213: GLPI is a free Asset and IT management software package2021-09-15