CVE-2021-43778

CRITICAL EXPLOITED IN THE WILD NUCLEI

GLPI <2.6.1 - Path Traversal

Title source: llm

Description

Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.

Exploits (1)

nomisec WORKING POC 3 stars
by AK-blank · infoleak
https://github.com/AK-blank/CVE-2021-43778

Nuclei Templates (1)

GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.
HIGHby cckuailong

Scores

CVSS v3 9.1
EPSS 0.9046
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

VulnCheck KEV 2022-05-31
InTheWild.io 2022-05-31
CWE
CWE-22
Status published
Products (1)
glpi-project/barcode 2.0 - 2.6.1
Published Nov 24, 2021
Tracked Since Feb 18, 2026