Cédric Anne
34 exploits
Active since Jul 2019
GLPI < 9.4.1 - Weak Password Recovery Mechanism for Forgotten Password
CVSS 5.9
GLPI < 9.5.2 - Unauthenticated Arbitrary File Deletion and Information Disclosure via pluginimage.send.php
CVSS 7.4
GLPI 0.65-10.0.11 - Cross-Site Scripting via Reports Page URL
CVSS 6.5
GLPI 10.0.8-10.0.12 - Unauthenticated Reflected Cross-Site Scripting via Debug Bar
CVSS 5.3
GLPI 0.80-10.0.16 - Unauthenticated User Email Enumeration via Application Endpoint
CVSS 7.5
GLPI 10.0.0-10.0.20 - Unauthenticated Document Access via Public FAQ
CVSS 7.5
GLPI 10.0.0-10.0.20 - Unauthenticated Document Access via Public FAQ
CVSS 7.5
GLPI < 9.5.2 - SQL Injection via Backtick Input
CVSS 8.7
GLPI < 9.5.2 - Unauthenticated Stored Cross-Site Scripting and Insecure Redirection via url_base Parameter
CVSS 8.0
GLPI 9.5.0-9.5.2 - Unauthenticated User Information Leakage via Public FAQ
CVSS 5.3
GLPI < 9.5.2 - Authenticated SQL Injection via API Search Function
CVSS 5.0
GLPI < 9.5.3 - Authenticated Unauthorized Planning Access via CalDAV
CVSS 7.7
GLPI < 9.5.7 - Authenticated SQL Injection
CVSS 4.9
GLPI < 10.0.0 - Stored Cross-Site Scripting via SVG Avatar Upload
CVSS 7.3
GLPI < 10.0.0 - Cross-Site Scripting via Ticket Followups or Login Message Stylesheet Link
CVSS 4.6
GLPI - Stored Cross-Site Scripting via Kanban User Name
CVSS 5.4
glpi-inventory-plugin < 1.0.2 - SQL Injection via Package Deployment Tasks
CVSS 5.8
GLPI < 10.0.3 - Cross-Site Scripting in Global Search
CVSS 6.8
GLPI < 10.0.3 - Stored Cross-Site Scripting in Registration Key Configuration Page
CVSS 6.3
GLPI < 10.0.3 - Authenticated SQL Injection via Plugin Controller
CVSS 5.5
GLPI < 10.0.3 - SQL Injection via External Token Login Simulation
CVSS 10.0
GLPI 0.84-9.5.12 - Server-Side Request Forgery via RSS Feed Autodiscovery
CVSS 3.5
Fields <1.13.1-1.20.4 - Privilege Escalation
CVSS 6.5
GLPI Order GLPI <2.7.7-2.10.1 - Command Injection
CVSS 8.8
GLPI 10.0.0-10.0.10 - SQL Injection via Saved Search Feature
CVSS 6.5