Stanislas

5 exploits Active since Sep 2022
CVE-2025-53360 WRITEUP MEDIUM WRITEUP
pluginsGLPI's Database Inventory Plugin <1.0.3 - Privilege Escalation
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior to 1.0.3, any authenticated user could send requests to agents. This issue has been patched in version 1.0.3.
CVSS 4.3
CVE-2025-53360 WRITEUP MEDIUM WRITEUP
pluginsGLPI's Database Inventory Plugin <1.0.3 - Privilege Escalation
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior to 1.0.3, any authenticated user could send requests to agents. This issue has been patched in version 1.0.3.
CVSS 4.3
CVE-2021-39190 WRITEUP MEDIUM WRITEUP
GLPI SCCM Plugin < 2.3.0 - Unauthenticated Information Disclosure via Configuration Page
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.
CVSS 5.3
CVE-2024-45600 WRITEUP HIGH WRITEUP
pluginsGLPI fields < 1.21.13 - Authenticated SQL Injection
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.
CVSS 7.7
CVE-2025-53360 WRITEUP MEDIUM WRITEUP
pluginsGLPI's Database Inventory Plugin <1.0.3 - Privilege Escalation
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior to 1.0.3, any authenticated user could send requests to agents. This issue has been patched in version 1.0.3.
CVSS 4.3