VendorsGLPi-projectglpi0.90.4
Vulnerabilities

GLPi-project GLPI 0.90.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2016-7507
Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.
Published 2017-07-19 · Modified
8.0EPSS 0.005
CVE-2016-7508
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.
Published 2017-06-21 · Modified
7.51 PoCEPSS 0.016
CVE-2016-7509
Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket.
Published 2017-07-19 · Modified
5.4EPSS 0.006