Vulnerabilities > Glpi Project > Glpi > High

DATE CVE VULNERABILITY TITLE RISK
2020-05-12 CVE-2020-11060 Cross-Site Request Forgery (CSRF) vulnerability in Glpi-Project Glpi
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality.
network
low complexity
glpi-project CWE-352
8.8
2020-05-05 CVE-2020-11033 Information Exposure vulnerability in multiple products
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User.
network
low complexity
glpi-project fedoraproject CWE-200
7.2
2020-05-05 CVE-2020-11032 SQL Injection vulnerability in Glpi-Project Glpi 9.4.5
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances.
network
low complexity
glpi-project CWE-89
7.2
2019-11-01 CVE-2013-2227 Improper Input Validation vulnerability in multiple products
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
network
low complexity
glpi-project debian CWE-20
7.5
2019-09-25 CVE-2019-14666 Information Exposure vulnerability in Glpi-Project Glpi
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature.
network
low complexity
glpi-project CWE-200
8.8
2019-03-27 CVE-2019-10233 Information Exposure Through Discrepancy vulnerability in Glpi-Project Glpi
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
network
high complexity
glpi-project CWE-203
8.1
2018-07-02 CVE-2018-13049 SQL Injection vulnerability in Glpi-Project Glpi
The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.
network
low complexity
glpi-project CWE-89
8.8
2018-03-12 CVE-2018-7562 Unrestricted Upload of File with Dangerous Type vulnerability in Glpi-Project Glpi
A remote code execution issue was discovered in GLPI through 9.2.1.
network
high complexity
glpi-project CWE-434
7.5
2017-07-20 CVE-2017-11475 SQL Injection vulnerability in Glpi-Project Glpi
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
network
low complexity
glpi-project CWE-89
8.8
2017-07-19 CVE-2016-7507 Cross-Site Request Forgery (CSRF) vulnerability in Glpi-Project Glpi 0.90.4
Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.
network
low complexity
glpi-project CWE-352
8.0