Описание
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.83.1-1 |
| hardy | ignored | end of life |
| lucid | ignored | end of life |
| maverick | ignored | end of life |
| natty | ignored | end of life |
| oneiric | ignored | end of life |
| precise | not-affected | 0.80.7-1 |
| quantal | not-affected | 0.83.1-1 |
| raring | not-affected | 0.83.1-1 |
| saucy | not-affected | 0.83.1-1 |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
Связанные уязвимости
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
The autocompletion functionality in GLPI before 0.80.2 does not blackl ...
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
EPSS
5 Medium
CVSS2