inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape4 action or (2) execute arbitrary PHP code via an update1 action.
It was found that GLPI, the Information Resource-Manager with an additional Administration-Interface, did not properly blacklist certain sensitive variables (like GLPI username and password). A remote attacker could use this flaw to obtain access to plaintext form of these values via specially-crafted HTTP POST request.
References: [1] http://www.glpi-project.org/spip.php?page=annonce&idbreve=237&lang=en [2] https://forge.indepnet.net/projects/glpi/versions/605 [3] https://forge.indepnet.net/issues/3017
Relevant patches: [4] https://forge.indepnet.net/projects/glpi/repository/revisions/14951 [5] https://forge.indepnet.net/projects/glpi/repository/revisions/14952 [6] https://forge.indepnet.net/projects/glpi/repository/revisions/14954 [7] https://forge.indepnet.net/projects/glpi/repository/revisions/14955 [8] https://forge.indepnet.net/projects/glpi/repository/revisions/14956 [9] https://forge.indepnet.net/projects/glpi/repository/revisions/14957 [10] https://forge.indepnet.net/projects/glpi/repository/revisions/14958 [11] https://forge.indepnet.net/projects/glpi/repository/revisions/14960 [12] https://forge.indepnet.net/projects/glpi/repository/revisions/14966
Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.