Versions of GLPI from 11.0.0 through 11.0.8 allow a specially‑made web address to display content that the attacker supplies. If a user clicks that link, the malicious content can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
Versions of GLPI from 11.0.0 through 11.0.8 allow a specially‑made web address to display content that the attacker supplies. If a user clicks that link, the malicious content can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
Versions 11.0.0 through 11.0.7 of the GLPI IT management tool let a user with form‑admin rights upload a specially crafted image that is saved outside the intended folder. This can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
Versions 11.0.0 through 11.0.7 of the GLPI IT management tool let a user with form‑admin rights upload a specially crafted image that is saved outside the intended folder. This can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions 11.0.6 through 11.0.8, a logged‑in technician can place hidden code in the supplier information fields. When any user opens the supplier list for that item, the hidden…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions 11.0.6 through 11.0.8, a logged‑in technician can place hidden code in the supplier information fields. When any user opens the supplier list for that item, the hidden…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions up to 10.0.26 and 11.0.8, a technician can use the API to alter another user's login type, even a super‑admin's. This could let the technician take over that account.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec
In GLPI versions up to 10.0.26 and 11.0.8, a technician can use the API to alter another user's login type, even a super‑admin's. This could let the technician take over that account.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#glpi #glpiproject #CVE #infosec