Vulnerabilities > Glpi Project > High

DATE CVE VULNERABILITY TITLE RISK
2021-11-24 CVE-2021-43778 Unspecified vulnerability in Glpi-Project Barcode
Barcode is a GLPI plugin for printing barcodes and QR codes.
network
low complexity
glpi-project
7.5
2021-09-15 CVE-2021-39213 Injection vulnerability in Glpi-Project Glpi
GLPI is a free Asset and IT management software package.
network
low complexity
glpi-project CWE-74
8.8
2021-09-15 CVE-2021-39209 Unspecified vulnerability in Glpi-Project Glpi
GLPI is a free Asset and IT management software package.
network
low complexity
glpi-project
8.8
2021-03-08 CVE-2021-21327 Unsafe Reflection vulnerability in Glpi-Project Glpi
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-470
7.5
2020-10-07 CVE-2020-15176 Unspecified vulnerability in Glpi-Project Glpi
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur.
network
low complexity
glpi-project
8.6
2020-09-23 CVE-2020-11031 Unspecified vulnerability in Glpi-Project Glpi
In GLPI before version 9.5.0, the encryption algorithm used is insecure.
network
low complexity
glpi-project
7.5
2020-07-17 CVE-2020-15108 SQL Injection vulnerability in Glpi-Project Glpi
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature.
network
low complexity
glpi-project CWE-89
7.1
2020-05-12 CVE-2020-11060 Cross-Site Request Forgery (CSRF) vulnerability in Glpi-Project Glpi
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality.
network
low complexity
glpi-project CWE-352
8.8
2020-05-05 CVE-2020-11033 Information Exposure vulnerability in multiple products
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User.
network
low complexity
glpi-project fedoraproject CWE-200
7.2
2020-05-05 CVE-2020-11032 SQL Injection vulnerability in Glpi-Project Glpi 9.4.5
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances.
network
low complexity
glpi-project CWE-89
7.2