
CVE-2024-27914 – Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI
https://notcve.org/view.php?id=CVE-2024-27914
18 Mar 2024 — GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13. GLPI es un paquete gratuito de software de gestión de TI y activos, gestión de centros de datos, ITIL Service Desk,... • https://github.com/shellkraft/CVE-2024-27914 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-27104 – Stored XSS in dashboards in GLPI
https://notcve.org/view.php?id=CVE-2024-27104
18 Mar 2024 — GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13. GLPI es un paquete gratuito de software de gestión de TI y activos, gestión de centros de datos, ITIL Service Desk, seguimiento de licencias y auditor... • https://github.com/glpi-project/glpi/commit/b409ca437864607b03c2014b9e3293b7f141af65 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-27098 – Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPI
https://notcve.org/view.php?id=CVE-2024-27098
18 Mar 2024 — GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13. GLPI es un paquete gratuito de software de gestión de TI y activos, gestión de centros de datos, ITIL Service Desk, seguimiento de licencias y auditoría de software. Un usuario autenticado puede ejecutar un ataque basado en SSRF ut... • https://github.com/glpi-project/glpi/commit/3b6bc1b4aa1f3693b20ada3425d2de5108522484 • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2024-27096 – SQL Injection in through the search engine
https://notcve.org/view.php?id=CVE-2024-27096
18 Mar 2024 — GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in the search engine to extract data from the database. This issue has been patched in version 10.0.13. GLPI es un paquete gratuito de software de gestión de TI y activos, gestión de centros de datos, ITIL Service Desk, seguimiento de licencias y auditoría de software. Un usuario autenticado puede aprovech... • https://github.com/glpi-project/glpi/commit/61a0c2302b4f633f5065358adc36058e1abc37f9 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-27930 – Sensitive fields access through dropdowns in GLPI
https://notcve.org/view.php?id=CVE-2024-27930
18 Mar 2024 — GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13. GLPI es un paquete gratuito de software de gestión de TI y activos, gestión de centros de datos, ITIL Service Desk, seguimiento de licencias y auditoría de software. Un usuario autenticado puede acceder a datos de campos confide... • https://borelenzo.github.io/stuff/2024/02/29/glpi-pwned.html • CWE-285: Improper Authorization •

CVE-2024-27937 – glpi Users emails enumeration
https://notcve.org/view.php?id=CVE-2024-27937
18 Mar 2024 — GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched in version 10.0.13. GLPI es un paquete gratuito de software de gestión de TI y activos, gestión de centros de datos, ITIL Service Desk, seguimiento de licencias y auditoría de software. Un usuario autenticado puede obtener la dirección de correo electrónico de todos los us... • https://borelenzo.github.io/stuff/2024/02/29/glpi-pwned.html • CWE-285: Improper Authorization •

CVE-2023-51446 – GLPI LDAP Injection during authentication
https://notcve.org/view.php?id=CVE-2023-51446
01 Feb 2024 — GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12. GLPI es un paquete gratuito de software de gestión de TI y activos. Cuando la autenticación se realiza contra un LDAP, el formulario de autenticación se puede utilizar para realizar la inyección de LDAP. • https://github.com/glpi-project/glpi/commit/58c67d78f2e3ad08264213e9aaf56eab3c9ded35 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') •

CVE-2024-23645 – GLPI reflected XSS in reports pages
https://notcve.org/view.php?id=CVE-2024-23645
01 Feb 2024 — GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12. GLPI es un paquete gratuito de software de gestión de TI y activos. Se puede utilizar una URL maliciosa para ejecutar XSS en páginas de informes. • https://github.com/glpi-project/glpi/commit/6cf265936c4f6edf7dea7c78b12e46d75b94d9b0 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-46727 – GLPI SQL injection through inventory agent request
https://notcve.org/view.php?id=CVE-2023-46727
13 Dec 2023 — GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory. GLPI es un paquete de software gratuito de gestión de activos y TI. • https://github.com/glpi-project/glpi/commit/ee2d674481ebef177037e8e14d35c9455b5cfd46 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-46726 – GLPI Remote code execution from LDAP server configuration form on PHP 7.4
https://notcve.org/view.php?id=CVE-2023-46726
13 Dec 2023 — GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI document. Version 10.0.11 contains a patch for the issue. GLPI es un paquete de software gratuito de gestión de activos y TI. A partir de la versión 10.0.0 y anteriores a la versión 10.0.11, solo en PHP 7.4, el formulario de configuración del servidor LDAP se puede utilizar par... • https://github.com/glpi-project/glpi/commit/42ba2b031bec0b3889317db25f3adf9080fc11b2 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •