Record summary

CVE-2021-39211 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheck, CVE List>= 9.2, < 9.5.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGLPI 9.2/<9.5.6 - Information DisclosureCVSS 5.3

GLPI 9.2 and prior to 9.5.6 is susceptible to information disclosure via the telemetry endpoint, which discloses GLPI and server information. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Information disclosure vulnerability in GLPI versions 9.2 to <9.5.6 allows an attacker to access sensitive information.

Remediation

This issue is fixed in version 9.5.6. As a workaround, remove the file ajax/telemetry.php, which is not needed for usual GLPI functions.

WeaknessesCWE-200
Authorsdogasantos, noraj
Template tagscvecve2021glpiexposureglpi-projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
Shodan: http.title:"glpi"
Shodan: http.favicon.hash:"-1474875778"
FOFA: icon_hash="-1474875778"
FOFA: title="glpi"
Google: intitle:"glpi"

Source: ProjectDiscovery

References

2