Логотип exploitDog
bind: "CVE-2025-21626"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-21626"

Количество 5

Количество 5

ubuntu логотип

CVE-2025-21626

4 месяца назад

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensitive values from the `name` field of the active LDAP directories, mail servers authentication providers and mail receivers.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2025-21626

4 месяца назад

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensitive values from the `name` field of the active LDAP directories, mail servers authentication providers and mail receivers.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2025-21626

4 месяца назад

GLPI is a free asset and IT management software package. Starting in v ...

CVSS3: 5.8
EPSS: Низкий
fstec логотип

BDU:2025-04043

4 месяца назад

Уязвимость системы заявок, инцидентов и инвентаризации компьютерного оборудования GLPI, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.8
EPSS: Низкий
redos логотип

ROS-20250402-04

3 месяца назад

Множественные уязвимости glpi

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-21626

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensitive values from the `name` field of the active LDAP directories, mail servers authentication providers and mail receivers.

CVSS3: 5.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-21626

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensitive values from the `name` field of the active LDAP directories, mail servers authentication providers and mail receivers.

CVSS3: 5.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-21626

GLPI is a free asset and IT management software package. Starting in v ...

CVSS3: 5.8
0%
Низкий
4 месяца назад
fstec логотип
BDU:2025-04043

Уязвимость системы заявок, инцидентов и инвентаризации компьютерного оборудования GLPI, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.8
0%
Низкий
4 месяца назад
redos логотип
ROS-20250402-04

Множественные уязвимости glpi

CVSS3: 7.5
3 месяца назад

Уязвимостей на страницу