CVE-2024-43416 : GLPI UP TO 10.0.16 INFORMATION DISCLOSURE

Description

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an application endpoint to check if an email address corresponds to a valid GLPI user. Version 10.0.17 fixes the issue.

References

https://github.com/glpi-project/glpi/security/advisories/GHSA-j8gc-xpgr-2ww7

https://github.com/glpi-project/glpi/commit/9be1466053f829680db318f7e7e5880d2d789c6d

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-47873 : PHPOFFICE PHPSPREADSHEET UP TO 1.29.3/2.1.2/2.3.1/3.3.X SCAN/FINDCHARSET XML EXTERNAL ENTITY REFERENCE

CVE-2024-47873 : PHPOFFICE PHPSPREADSHEET UP TO 1.29.3/2.1.2/2.3.1/3.3.X SCAN/FINDCHARSET XML EXTERNAL ENTITY REFERENCE

Description PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which

CVE-2024-43416 : GLPI UP TO 10.0.16 INFORMATION DISCLOSURE

CVE-2024-43416 : GLPI UP TO 10.0.16 INFORMATION DISCLOSURE

Description GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17,

CVE-2024-0012 : PALO ALTO NETWORKS PAN-OS MANAGEMENT WEB INTERFACE MISSING AUTHENTICATION

CVE-2024-0012 : PALO ALTO NETWORKS PAN-OS MANAGEMENT WEB INTERFACE MISSING AUTHENTICATION

Description An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management