Show filters
170 Total Results
Displaying 51-60 of 170
Sort by:
Attacker Value
Unknown
CVE-2023-36808
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.
0
Attacker Value
Unknown
CVE-2023-35940
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2023-35939
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat actor to interact, modify, or see Dashboard data. Version 10.0.8 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2023-35924
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.
0
Attacker Value
Unknown
CVE-2023-34244
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
GLPI is a free asset and IT management software package. Starting in version 9.4.0 and prior to version 10.0.8, a malicious link can be crafted by an unauthenticated user that can exploit a reflected XSS in case any authenticated user opens the crafted link. Users should upgrade to version 10.0.8 to receive a patch.
0
Attacker Value
Unknown
CVE-2023-34107
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch for this issue.
0
Attacker Value
Unknown
CVE-2023-34106
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information. Users should upgrade to version 10.0.8 to receive a patch.
0
Attacker Value
Unknown
CVE-2023-34254
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh command, an administrator user on the remote can manage to inject a command in a specific workflow the agent would run with the privileges it uses. In the case, the agent is running with administration privileges, a malicious user could gain high privileges on the computer glpi-agent is running on. A malicious user could also disclose all remote accesses the agent is configured with for remoteinventory task. This vulnerability has been patched in glpi-agent 1.5.
0
Attacker Value
Unknown
CVE-2022-34128
Disclosure Date: April 16, 2023 (last updated October 08, 2023)
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
0
Attacker Value
Unknown
CVE-2022-34127
Disclosure Date: April 16, 2023 (last updated October 08, 2023)
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.
0