First published: Wed Nov 24 2021(Updated: )
Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI Project Barcode | >=2.0<2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43778 is classified as a path traversal vulnerability that could expose sensitive files.
To fix CVE-2021-43778, upgrade the GLPI Barcode Plugin to version 2.6.1 or later.
CVE-2021-43778 affects GLPI Barcode Plugin versions 2.x prior to 2.6.1.
Exploiting CVE-2021-43778 can lead to unauthorized access to files on the server.
Yes, as a temporary workaround, you can delete the front/send.php file in the GLPI installation.