CVE-2023-51446 – GLPI LDAP Injection during authentication
https://notcve.org/view.php?id=CVE-2023-51446
GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12. GLPI es un paquete gratuito de software de gestión de TI y activos. Cuando la autenticación se realiza contra un LDAP, el formulario de autenticación se puede utilizar para realizar la inyección de LDAP. • https://github.com/glpi-project/glpi/commit/58c67d78f2e3ad08264213e9aaf56eab3c9ded35 https://github.com/glpi-project/glpi/releases/tag/10.0.12 https://github.com/glpi-project/glpi/security/advisories/GHSA-p995-jmfv-c7r8 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') •
CVE-2024-23645 – GLPI reflected XSS in reports pages
https://notcve.org/view.php?id=CVE-2024-23645
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12. GLPI es un paquete gratuito de software de gestión de TI y activos. Se puede utilizar una URL maliciosa para ejecutar XSS en páginas de informes. • https://github.com/glpi-project/glpi/commit/6cf265936c4f6edf7dea7c78b12e46d75b94d9b0 https://github.com/glpi-project/glpi/commit/fc1f6da9d158933b870ff374ed3a50ae98dcef4a https://github.com/glpi-project/glpi/releases/tag/10.0.12 https://github.com/glpi-project/glpi/security/advisories/GHSA-2gj5-qpff-ff3x • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-41324 – Account takeover through API in GLPI
https://notcve.org/view.php?id=CVE-2023-41324
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user that have read access on users resource can steal accounts of other users. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. Gestionnaire Libre de Parc Informatique (GLPI) es un paquete Gratuito de Software de Gestión de Activos IT, que proporciona funciones de ITIL Service Desk, seguimiento de licencias y auditoría de software. • https://github.com/glpi-project/glpi/security/advisories/GHSA-58wj-8jhx-jpm3 • CWE-269: Improper Privilege Management •
CVE-2023-41323 – Users login enumeration by unauthenticated user in GLPI
https://notcve.org/view.php?id=CVE-2023-41323
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can enumerate users logins. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. Gestionnaire Libre de Parc Informatique (GLPI) es un paquete Gratuito de Software de Gestión de Activos IT, que proporciona funciones de ITIL Service Desk, seguimiento de licencias y auditoría de software. • https://github.com/glpi-project/glpi/security/advisories/GHSA-5cf4-6q6r-49x9 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-41322 – Privilege Escalation from technician to super-admin in GLPI
https://notcve.org/view.php?id=CVE-2023-41322
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's password and then take control of their account. Users are advised to upgrade to version 10.0.10. There are no known work around for this vulnerability. Gestionnaire Libre de Parc Informatique (GLPI) es un paquete Gratuito de Software de Gestión de Activos IT, que proporciona funciones de ITIL Service Desk, seguimiento de licencias y auditoría de software. • https://github.com/glpi-project/glpi/security/advisories/GHSA-9j8m-7563-8xvr • CWE-269: Improper Privilege Management CWE-284: Improper Access Control •