GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 0.72
A vulnerability exists in GLPI versions 0.72 and prior to 10.0.18, allowing anonymous users to disable all active plugins. This issue arises from insufficient access controls, enabling unauthorized users to manipulate plugin settings. The vulnerability can be exploited without any special requirements or user interaction.
Exploitation of this vulnerability leads to the unauthorized disabling of all active plugins, which could disrupt functionality and user experience.
Users are advised to upgrade to GLPI version 10.0.18, which addresses this vulnerability. As an additional step, the 'install/update.php' file can be deleted to mitigate the issue.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.