PHPStan rules for GLPI.
🔗 https://github.com/glpi-project/phpstan-glpi
PHPStan rules for GLPI.
🔗 https://github.com/glpi-project/phpstan-glpi
https://github.com/NixOS/nixpkgs/pull/567587
#security
https://github.com/NixOS/nixpkgs/pull/567587
#security
Versions 11.0.0 through 11.0.7 of the GLPI IT management tool let a user with form‑admin rights upload a specially crafted image that is saved outside the intended folder. This can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
Versions 11.0.0 through 11.0.7 of the GLPI IT management tool let a user with form‑admin rights upload a specially crafted image that is saved outside the intended folder. This can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions up to 10.0.26 and 11.0.8, a technician can use the API to alter another user's login type, even a super‑admin's. This could let the technician take over that account.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions up to 10.0.26 and 11.0.8, a technician can use the API to alter another user's login type, even a super‑admin's. This could let the technician take over that account.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
Versions of GLPI from 11.0.0 through 11.0.8 allow a specially‑made web address to display content that the attacker supplies. If a user clicks that link, the malicious content can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
Versions of GLPI from 11.0.0 through 11.0.8 allow a specially‑made web address to display content that the attacker supplies. If a user clicks that link, the malicious content can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions 11.0.6 through 11.0.8, a logged‑in technician can place hidden code in the supplier information fields. When any user opens the supplier list for that item, the hidden…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions 11.0.6 through 11.0.8, a logged‑in technician can place hidden code in the supplier information fields. When any user opens the supplier list for that item, the hidden…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
本日公開されたMediawiki、GLPI、MCMSの重要脆弱性3件について、OSコマンドインジェクションやRCEの危険性があるため、早急な確認と対応が求められます。
本日公開されたMediawiki、GLPI、MCMSの重要脆弱性3件について、OSコマンドインジェクションやRCEの危険性があるため、早急な確認と対応が求められます。
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can...
🔎 https://stemshop.top/cve/CVE-2026-48482
#CVE #CyberSecurity #InfoSec
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can...
🔎 https://stemshop.top/cve/CVE-2026-48482
#CVE #CyberSecurity #InfoSec
📊 7.7/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not li...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87282
#cybersecurity #infosec #cve #euvd
📊 7.7/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not li...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87282
#cybersecurity #infosec #cve #euvd
📊 8.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier we...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87283
#cybersecurity #infosec #cve #euvd
📊 8.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier we...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87283
#cybersecurity #infosec #cve #euvd
📊 7.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87285
#cybersecurity #infosec #cve #euvd
📊 7.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87285
#cybersecurity #infosec #cve #euvd
📊 9.4/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustrati...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87287
#cybersecurity #infosec #cve #euvd
📊 9.4/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustrati...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87287
#cybersecurity #infosec #cve #euvd
📊 7.1/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a d...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87288
#cybersecurity #infosec #cve #euvd
📊 7.1/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a d...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87288
#cybersecurity #infosec #cve #euvd
📊 7.1/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87289
#cybersecurity #infosec #cve #euvd
📊 7.1/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87289
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87280
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87280
#cybersecurity #infosec #cve #euvd
📊 8.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87284
#cybersecurity #infosec #cve #euvd
📊 8.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87284
#cybersecurity #infosec #cve #euvd
📊 7.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87286
#cybersecurity #infosec #cve #euvd
📊 7.5/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87286
#cybersecurity #infosec #cve #euvd
📊 4.6/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit craft...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87272
#cybersecurity #infosec #cve #euvd
📊 4.6/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit craft...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87272
#cybersecurity #infosec #cve #euvd
📊 6.0/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to pe...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87273
#cybersecurity #infosec #cve #euvd
📊 6.0/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to pe...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87273
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission ca...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87274
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission ca...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87274
#cybersecurity #infosec #cve #euvd
📊 5.9/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Upd...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87275
#cybersecurity #infosec #cve #euvd
📊 5.9/10
🏢 glpi-project
📝 GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Upd...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87275
#cybersecurity #infosec #cve #euvd