Vulnerabilities > Glpi Project > Glpi > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-03-03 | CVE-2021-21312 | Unspecified vulnerability in Glpi-Project Glpi GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. | 4.8 |
2021-03-02 | CVE-2021-21258 | Unspecified vulnerability in Glpi-Project Glpi GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. | 5.4 |
2021-03-02 | CVE-2021-21255 | Authorization Bypass Through User-Controlled Key vulnerability in Glpi-Project Glpi 9.5.3 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. | 5.7 |
2020-11-26 | CVE-2020-27663 | Authorization Bypass Through User-Controlled Key vulnerability in Glpi-Project Glpi In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.). | 4.3 |
2020-11-26 | CVE-2020-27662 | Authorization Bypass Through User-Controlled Key vulnerability in Glpi-Project Glpi In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.). | 4.3 |
2020-11-25 | CVE-2020-26212 | Unspecified vulnerability in Glpi-Project Glpi GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. | 6.5 |
2020-10-07 | CVE-2020-15226 | Unspecified vulnerability in Glpi-Project Glpi In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. | 4.3 |
2020-10-07 | CVE-2020-15217 | Unspecified vulnerability in Glpi-Project Glpi 9.5.0/9.5.1 In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. | 5.3 |
2020-10-07 | CVE-2020-15177 | Unspecified vulnerability in Glpi-Project Glpi In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. | 6.1 |
2020-05-12 | CVE-2020-11062 | Cross-site Scripting vulnerability in Glpi-Project Glpi In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. | 5.4 |