Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11955

Опубликовано: 25 фев. 2025
Источник: nvd
CVSS3: 4.3
CVSS3: 6.1
CVSS2: 5
EPSS Низкий

Описание

A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.0.18 is able to address this issue. It is recommended to upgrade the affected component.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
Версия от 0.85 (включая) до 10.0.18 (исключая)

EPSS

Процентиль: 32%
0.0012
Низкий

4.3 Medium

CVSS3

6.1 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.3
ubuntu
9 месяцев назад

A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.0.18 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 4.3
debian
9 месяцев назад

A vulnerability was found in GLPI up to 10.0.17. It has been declared ...

CVSS3: 4.3
fstec
9 месяцев назад

Уязвимость системы заявок, инцидентов и инвентаризации компьютерного оборудования GLPI, связанная с переадресацией URL на ненадежный сайт при обработке параметра redirect, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 4.3
redos
около 2 месяцев назад

Уязвимость glpi

EPSS

Процентиль: 32%
0.0012
Низкий

4.3 Medium

CVSS3

6.1 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-601