GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 0.78, < 11.0.0
- >= 11.0.0
A vulnerability in GLPI versions 0.78 prior to 10.0.25 and 11.0.0 prior to 11.0.7 allows technicians to delete arbitrary files from the filesystem, provided the webserver has write permissions on those files. This issue arises from insufficient restrictions on file deletion capabilities.
Exploitation of this vulnerability could lead to unauthorized deletion of files, potentially causing data loss or disruption of services.
Users are advised to upgrade to GLPI version 10.0.25 or 11.0.7, both of which include the necessary patch.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.