CVE-2021-39211
Disclosure of GLPI and server information in telemetry endpoint
Record summary
CVE-2021-39211 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck, CVE List | >= 9.2, < 9.5.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMGLPI 9.2/<9.5.6 - Information DisclosureCVSS 5.3
GLPI 9.2 and prior to 9.5.6 is susceptible to information disclosure via the telemetry endpoint, which discloses GLPI and server information. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
Information disclosure vulnerability in GLPI versions 9.2 to <9.5.6 allows an attacker to access sensitive information.
Remediation
This issue is fixed in version 9.5.6. As a workaround, remove the file ajax/telemetry.php, which is not needed for usual GLPI functions.
Source: ProjectDiscovery