Glpi-Project Glpi vulnerabilities
193 known vulnerabilities affecting glpi-project/glpi.
Total CVEs
193
CISA KEV
1
actively exploited
Public exploits
15
Exploited in wild
1
Severity breakdown
CRITICAL27HIGH53MEDIUM111LOW2
Vulnerabilities
Page 9 of 10
CVE-2020-11034MEDIUMCVSS 6.1PoCfixed in 9.4.62020-05-05
CVE-2020-11034 [MEDIUM] CWE-185 CVE-2020-11034: In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect prote
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
nvd
CVE-2012-1104MEDIUMCVSS 5.3≥ 0, < 0.84.3+dfsg.1-12019-12-05
CVE-2012-1104 [MEDIUM] CVE-2012-1104: A Security Bypass vulnerability exists in the phpCAS 1
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
osv
CVE-2012-1105MEDIUMCVSS 5.5≥ 0, < 0.84.3+dfsg.1-12019-12-05
CVE-2012-1105 [MEDIUM] CVE-2012-1105: An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
osv
CVE-2013-2227HIGHCVSS 7.5PoCv0.83.72019-11-01
CVE-2013-2227 [HIGH] CWE-20 CVE-2013-2227: GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
nvdosv
CVE-2019-14666HIGHCVSS 8.8≤ 9.4.32019-09-25
CVE-2019-14666 [HIGH] CWE-200 CVE-2019-14666: GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletio
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control o
nvd
CVE-2019-1010307MEDIUMCVSS 5.4v9.3.12019-07-15
CVE-2019-1010307 [MEDIUM] CWE-79 CVE-2019-1010307: GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown valu
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and click on the "Link Tickets" fea
nvd
CVE-2019-1010310LOWCVSS 3.5v9.3.12019-07-12
CVE-2019-1010310 [LOW] CWE-74 CVE-2019-1010310: GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any iframe/form tags and apply. The attack
nvd
CVE-2019-13240MEDIUMCVSS 5.9fixed in 9.4.12019-07-10
CVE-2019-13240 [MEDIUM] CWE-640 CVE-2019-13240: An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is pos
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
nvd
CVE-2019-13239MEDIUMCVSS 6.1≥ 9.1, < 9.4.32019-07-04
CVE-2019-13239 [MEDIUM] CWE-79 CVE-2019-13239: inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
nvd
CVE-2019-10233HIGHCVSS 8.1fixed in 9.4.1.12019-03-27
CVE-2019-10233 [HIGH] CWE-203 CVE-2019-10233: Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
nvd
CVE-2018-13049HIGHCVSS 8.8≥ 9.2.0, ≤ 9.3.02018-07-02
CVE-2018-13049 [HIGH] CWE-89 CVE-2018-13049: The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection,
The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.
nvd
CVE-2018-7562HIGHCVSS 7.5≤ 9.2.12018-03-12
CVE-2018-7562 [HIGH] CWE-362 CVE-2018-7562: A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that a
A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated user to upload a file when he/she creates a new ticket via front/fileupload.php. This feature is protected using different types of secu
nvd
CVE-2018-7563MEDIUMCVSS 6.1≤ 9.2.12018-03-12
CVE-2018-7563 [MEDIUM] CWE-79 CVE-2018-7563: An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query strin
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of action
nvd
CVE-2017-11184CRITICALCVSS 9.8≤ 9.1.42017-07-28
CVE-2017-11184 [CRITICAL] CWE-89 CVE-2017-11184: SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
nvd
CVE-2017-11183MEDIUMCVSS 4.9≤ 9.1.42017-07-28
CVE-2017-11183 [MEDIUM] CWE-20 CVE-2017-11183: front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
nvd
CVE-2017-11474CRITICALCVSS 9.8≤ 9.1.5.02017-07-20
CVE-2017-11474 [CRITICAL] CWE-89 CVE-2017-11474: GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.ph
GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.
nvd
CVE-2017-11475HIGHCVSS 8.8≤ 9.1.5.02017-07-20
CVE-2017-11475 [HIGH] CWE-89 CVE-2017-11475: GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
nvd
CVE-2016-7507HIGHCVSS 8.0v0.90.42017-07-19
CVE-2016-7507 [HIGH] CWE-352 CVE-2016-7507: Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers
Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.
nvd
CVE-2016-7509MEDIUMCVSS 5.4v0.90.42017-07-19
CVE-2016-7509 [MEDIUM] CWE-79 CVE-2016-7509: Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inj
Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket.
nvd
CVE-2017-11329CRITICALCVSS 9.8≤ 9.1.42017-07-17
CVE-2017-11329 [CRITICAL] CWE-89 CVE-2017-11329: GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restr
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
nvd