GLPI 是一套免费的资产与IT管理软件套件。从版本 11.0.0 到 11.0.8,低权限的已认证用户可以利用新的 API(v2)执行通常通过用户界面被禁止的更新操作。API 的更新流程未始终一致地执行适用的授权检查。此问题已在版本 11.0.8 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| glpi-project | glpi | >= 11.0.0, < 11.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48482 | 9.4 CRITICAL | GLPI: RCE via Form import |
| CVE-2026-47679 | 8.5 HIGH | GLPI: arbitrary file deletion |
| CVE-2026-55214 | 8.5 HIGH | GLPI: Stored XSS in suppliers |
| CVE-2026-49470 | 7.7 HIGH | GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute Fo |
| CVE-2026-53625 | 7.5 HIGH | GLPI: Privilege Escalation via authtype API manipulation |
| CVE-2026-53610 | 7.5 HIGH | GLPI: Reflected XSS in dashboards |
| CVE-2026-53629 | 7.1 HIGH | GLPI: SQL injection in history tab |
| CVE-2026-53626 | 7.1 HIGH | GLPI: Arbitrary Document Read via Form Context Authorization Bypass |
| CVE-2026-53628 | 5.9 MEDIUM | GLPI: Unallowed authentication method update by administrator |
| CVE-2026-45801 | 5.3 MEDIUM | GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation) |
| CVE-2026-55217 | 5.3 MEDIUM | GLPI: Unallowed modfication of knowbase items comments and translations |
| CVE-2026-49469 | 4.6 MEDIUM | GLPI: LDAP filter injection in user import feature |
No comments yet