CVE-2020-15217

Source
https://cve.org/CVERecord?id=CVE-2020-15217
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15217.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-15217
Related
  • GHSA-x9hg-j29f-wvvv
Published
2020-10-07T19:15:12.907Z
Modified
2026-02-07T22:16:07.923243Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.

References

Affected packages

Git / github.com/glpi-project/glpi

Affected ranges

Affected versions

9.*
9.5.0
9.5.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15217.json"