Search CVE reports


Toggle filters

151 – 160 of 224 results


CVE-2022-24867

Medium priority

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi — — — — —
Show less packages

CVE-2022-21720

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release —
Show less packages

CVE-2022-21719

Medium priority
Needs evaluation

GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release —
Show less packages

CVE-2021-43779

Low priority
Vulnerable

GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi — — — — —
Show less packages

CVE-2021-39213

Medium priority
Vulnerable

GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-39211

Medium priority
Vulnerable

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround,...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-39210

Medium priority
Vulnerable

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-39209

Medium priority
Vulnerable

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-3486

Medium priority
Vulnerable

GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-21327

Medium priority
Vulnerable

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object...

1 affected package

glpi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glpi Not in release Not in release Not in release Not in release Not in release
Show less packages