Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-39210

Опубликовано: 15 сент. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 3.5
EPSS Низкий

Описание

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
Версия до 9.5.6 (исключая)

EPSS

Процентиль: 50%
0.00266
Низкий

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-1004
CWE-732

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.

CVSS3: 6.5
debian
больше 4 лет назад

GLPI is a free Asset and IT management software package. In versions p ...

EPSS

Процентиль: 50%
0.00266
Низкий

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-1004
CWE-732