Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Orthagh

#16942of 53,622
15.9Total CVSS
Vulnerabilities · 2
High
2
PT-2020-12500
7.8
2020-09-23
Teclib · Glpi · CVE-2020-11031
**Name of the Vulnerable Software and Affected Versions** GLPI versions prior to 9.5.0 **Description** The issue is related to an insecure encryption algorithm used in the software. The security of the encrypted data relies on the password used, and if a user sets a weak or predictable password, an attacker could potentially decrypt the data. A more secure encryption library, sodium, is used in the fixed version to address this issue. **Recommendations** For versions prior to 9.5.0, update to version 9.5.0 or later, which uses a more secure encryption library to mitigate the risk.
PT-2019-11648
8.1
2019-03-27
Teclib · Glpi · CVE-2019-10233
Name of the Vulnerable Software and Affected Versions: GLPI versions prior to 9.4.1.1 Description: The issue is related to a timing attack associated with a cookie. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited. Recommendations: For versions prior to 9.4.1.1, update to version 9.4.1.1 or later to resolve the issue.