Show filters
170 Total Results
Displaying 11-20 of 170
Sort by:
Attacker Value
Unknown

CVE-2024-38370

Disclosure Date: November 15, 2024 (last updated February 11, 2025)
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
Attacker Value
Unknown

CVE-2024-45611

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can bypass the access control policy to create a private RSS feed attached to another user account and use a malicious payload to triggger a stored XSS. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-45610

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Cable form. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-45609

Disclosure Date: November 15, 2024 (last updated November 20, 2024)
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the reports pages. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-45608

Disclosure Date: November 15, 2024 (last updated November 21, 2024)
GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-43418

Disclosure Date: November 15, 2024 (last updated November 21, 2024)
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-43417

Disclosure Date: November 15, 2024 (last updated November 21, 2024)
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Software form. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-41679

Disclosure Date: November 15, 2024 (last updated November 21, 2024)
GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-47759

Disclosure Date: November 15, 2024 (last updated January 24, 2025)
GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.
Attacker Value
Unknown

CVE-2024-41678

Disclosure Date: November 15, 2024 (last updated November 21, 2024)
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.