Vulnerabilities > Glpi Project > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-26 CVE-2020-27662 Authorization Bypass Through User-Controlled Key vulnerability in Glpi-Project Glpi
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).
network
low complexity
glpi-project CWE-639
4.3
2020-11-25 CVE-2020-26212 Unspecified vulnerability in Glpi-Project Glpi
GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing.
network
low complexity
glpi-project
6.5
2020-10-07 CVE-2020-15226 Unspecified vulnerability in Glpi-Project Glpi
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function.
network
low complexity
glpi-project
4.3
2020-10-07 CVE-2020-15217 Unspecified vulnerability in Glpi-Project Glpi 9.5.0/9.5.1
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ.
network
low complexity
glpi-project
5.3
2020-10-07 CVE-2020-15177 Unspecified vulnerability in Glpi-Project Glpi
In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`.
network
low complexity
glpi-project
6.1
2020-05-12 CVE-2020-11062 Cross-site Scripting vulnerability in Glpi-Project Glpi
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type.
network
low complexity
glpi-project CWE-79
5.4
2020-05-12 CVE-2020-5248 Use of Hard-coded Credentials vulnerability in Glpi-Project Glpi
GLPI before before version 9.4.6 has a vulnerability involving a default encryption key.
network
low complexity
glpi-project CWE-798
5.3
2020-05-05 CVE-2020-11036 Cross-site Scripting vulnerability in Glpi-Project Glpi
In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities.
network
low complexity
glpi-project CWE-79
5.4
2020-05-05 CVE-2020-11034 Open Redirect vulnerability in Glpi-Project Glpi
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp.
network
low complexity
glpi-project CWE-601
6.1
2019-07-15 CVE-2019-1010307 Cross-site Scripting vulnerability in Glpi-Project Glpi 9.3.1
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS).
network
low complexity
glpi-project CWE-79
5.4