← back
CVE-2021-39211mediumobserved exploitationCWE-200

Disclosure of GLPI and server information in telemetry endpoint

50Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 5.3epss 4.7%
from disclosure to weapon
Published on NVDSep 15
VulnCheck+789d
exploitation probability
4.7%top 9% of all CVEs
observed exploitation
yesVulnCheck
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
glpi-project · glpi