GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 0.71
A vulnerability allowing the exposure of sensitive information has been identified in GLPI versions 0.71 and prior to 10.0.18. An anonymous user can access this information through the status.php endpoint. The vulnerability arises from inadequate access controls, allowing unauthorized users to retrieve sensitive data.
Exploitation of this vulnerability allows for the unauthorized retrieval of sensitive information from the status.php endpoint.
Users are advised to upgrade to GLPI version 10.0.18, which addresses this vulnerability. Alternatively, the status.php file can be deleted, access to it can be restricted, or sensitive values can be removed from the name field of active LDAP directories, mail server authentication providers, and mail receivers.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.