Back to Database
Status published
Medium
CVE-2013-2225
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to...
Vulnerability Description
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-2225
Credits & Attribution
No credits recorded in the NVD database.
References
More from glpi-project
View All →CVE-2025-66417
GLPI has an unauthenticated SQL injection through the inventory endpoint
High
7.5
CVE-2025-64520
GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API
Medium
6.5
CVE-2025-64516
GLPI incorrectly authorizes access to documents
High
7.5
CVE-2025-59935
GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page
Medium
6.5
CVE-2025-53357
GLPI permits reservation modification by unauthorized users
Medium
5.4
Affected Vendor
glpi-project
View all reports →Affected Software
glpi
Vulnerable Versions:
0, 0.5, 0.6, 0.20, 0.21, 0.30, 0.31, 0.40, 0.41, 0.42, 0.51, 0.51a, 0.65, 0.68, 0.68.1, 0.68.2, 0.68.3, 0.70, 0.70.1, 0.70.2, 0.71, 0.71.1, 0.71.2, 0.71.3, 0.71.4, 0.71.5, 0.71.6, 0.72, 0.72.1, 0.72.2, 0.72.3, 0.72.4, 0.78, 0.78.1, 0.78.2, 0.78.3, 0.78.4, 0.78.5, 0.80, 0.80.1, 0.80.2, 0.80.3, 0.80.4, 0.80.5, 0.80.6, 0.80.7, 0.80.61, 0.83, 0.83.1, 0.83.2, 0.83.3, 0.83.4, 0.83.5, 0.83.6, 0.83.7, 0.83.8, 0.83.31
Timeline
Official Publish:
May 27th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.