Vulnerabilities > Glpi Project > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-11-26 | CVE-2020-27662 | Insecure Storage of Sensitive Information vulnerability in Glpi-Project Glpi In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.). | 4.0 |
2020-11-25 | CVE-2020-26212 | Missing Authorization vulnerability in Glpi-Project Glpi GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. | 4.0 |
2020-10-07 | CVE-2020-15226 | SQL Injection vulnerability in Glpi-Project Glpi In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. | 5.0 |
2020-10-07 | CVE-2020-15217 | Cross-site Scripting vulnerability in Glpi-Project Glpi 9.5.0/9.5.1 In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. | 5.0 |
2020-10-07 | CVE-2020-15177 | Cross-site Scripting vulnerability in Glpi-Project Glpi In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. | 4.3 |
2020-10-07 | CVE-2020-15176 | SQL Injection vulnerability in Glpi-Project Glpi In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. | 5.0 |
2020-09-23 | CVE-2020-11031 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Glpi-Project Glpi In GLPI before version 9.5.0, the encryption algorithm used is insecure. | 5.0 |
2020-07-17 | CVE-2020-15108 | SQL Injection vulnerability in Glpi-Project Glpi In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. | 4.0 |
2020-05-12 | CVE-2020-5248 | Use of Hard-coded Credentials vulnerability in Glpi-Project Glpi GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. | 5.0 |
2020-05-05 | CVE-2020-11036 | Cross-site Scripting vulnerability in Glpi-Project Glpi In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. | 5.4 |