← back
CVE-2021-39213mediumCWE-74

IP restriction on GLPI API Bypass with custom header injection

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 1.1%
exploitation probability
1.1%top 39% of all CVEs
observed exploitation
nono source reports it
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
glpi-project · glpi