Vulnerabilities > Glpi Project > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-15 | CVE-2021-39211 | Unspecified vulnerability in Glpi-Project Glpi GLPI is a free Asset and IT management software package. | 5.0 |
2021-09-15 | CVE-2021-39213 | Injection vulnerability in Glpi-Project Glpi GLPI is a free Asset and IT management software package. | 6.0 |
2021-09-15 | CVE-2021-39209 | Cross-Site Request Forgery (CSRF) vulnerability in Glpi-Project Glpi GLPI is a free Asset and IT management software package. | 6.8 |
2021-05-26 | CVE-2021-3486 | Cross-site Scripting vulnerability in Glpi-Project Glpi 9.5.4 GLPi 9.5.4 does not sanitize the metadata. | 6.1 |
2021-04-06 | CVE-2021-30144 | Forced Browsing vulnerability in Glpi-Project Dashboard The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. | 4.3 |
2021-03-08 | CVE-2021-21326 | Missing Authorization vulnerability in Glpi-Project Glpi GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. | 4.0 |
2021-03-08 | CVE-2021-21324 | Authorization Bypass Through User-Controlled Key vulnerability in Glpi-Project Glpi GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. | 4.0 |
2021-03-03 | CVE-2021-21313 | Cross-site Scripting vulnerability in Glpi-Project Glpi GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. | 6.1 |
2021-03-02 | CVE-2021-21255 | Authorization Bypass Through User-Controlled Key vulnerability in Glpi-Project Glpi 9.5.3 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. | 5.7 |
2020-11-26 | CVE-2020-27663 | Insecure Storage of Sensitive Information vulnerability in Glpi-Project Glpi In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.). | 4.0 |