Teclib · Glpi · CVE-2020-11031
**Name of the Vulnerable Software and Affected Versions**
GLPI versions prior to 9.5.0
**Description**
The issue is related to an insecure encryption algorithm used in the software. The security of the encrypted data relies on the password used, and if a user sets a weak or predictable password, an attacker could potentially decrypt the data. A more secure encryption library, sodium, is used in the fixed version to address this issue.
**Recommendations**
For versions prior to 9.5.0, update to version 9.5.0 or later, which uses a more secure encryption library to mitigate the risk.