← Back

CVE-2013-5696

nvd nist
Published: Sep 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.

Affected (79)

Products: Glpi Project: Glpi
1 product
Glpi
Configuration A
79 vulnerable
Vulnerable SoftwareAffected Versions
Glpi Project
Up to 0.84.1
Version 0.20
Version 0.21
Version 0.30
Version 0.31
Version 0.40
Version 0.41
Version 0.42
Version 0.51
Version 0.51a
Version 0.5
Version 0.5 rc1
Version 0.5 rc2
Version 0.65
Version 0.65 rc1
Version 0.65 rc2
Version 0.68.1
Version 0.68.2
Version 0.68.3
Version 0.68
Version 0.68 rc1
Version 0.68 rc2
Version 0.68 rc3
Version 0.6
Version 0.6 rc1
Version 0.6 rc2
Version 0.6 rc3
Version 0.70.1
Version 0.70.2
Version 0.70
Version 0.70 rc1
Version 0.70 rc2
Version 0.70 rc3
Version 0.71.1
Version 0.71.1 rc1
Version 0.71.1 rc2
Version 0.71.1 rc3
Version 0.71.2
Version 0.71.3
Version 0.71.4
Version 0.71.5
Version 0.71.6
Version 0.71
Version 0.72.1
Version 0.72.2
Version 0.72.3
Version 0.72.4
Version 0.72
Version 0.72 rc1
Version 0.72 rc2
Version 0.72 rc3
Version 0.78.1
Version 0.78.2
Version 0.78.3
Version 0.78.4
Version 0.78.5
Version 0.78
Version 0.80.1
Version 0.80.2
Version 0.80.3
Version 0.80.4
Version 0.80.5
Version 0.80.61
Version 0.80.6
Version 0.80.7
Version 0.80
Version 0.83.1
Version 0.83.2
Version 0.83.31
Version 0.83.3
Version 0.83.4
Version 0.83.5
Version 0.83.6
Version 0.83.7
Version 0.83.8
Version 0.83.91
Version 0.83.9
Version 0.83
Version 0.84

Timeline

No history available yet.