CVE-2013-5696 - CVE House
Back to Database
Status published Medium CVE-2013-5696

inc/central.class.php in GLPI before 0.84.2 does not attempt to make...

Vulnerability Description

inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-5696

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

glpi-project

View all reports →

Affected Software

glpi
Vulnerable Versions:
0, 0.5, 0.6, 0.20, 0.21, 0.30, 0.31, 0.40, 0.41, 0.42, 0.51, 0.51a, 0.65, 0.68, 0.68.1, 0.68.2, 0.68.3, 0.70, 0.70.1, 0.70.2, 0.71, 0.71.1, 0.71.2, 0.71.3, 0.71.4, 0.71.5, 0.71.6, 0.72, 0.72.1, 0.72.2, 0.72.3, 0.72.4, 0.78, 0.78.1, 0.78.2, 0.78.3, 0.78.4, 0.78.5, 0.80, 0.80.1, 0.80.2, 0.80.3, 0.80.4, 0.80.5, 0.80.6, 0.80.7, 0.80.61, 0.83, 0.83.1, 0.83.2, 0.83.3, 0.83.4, 0.83.5, 0.83.6, 0.83.7, 0.83.8, 0.83.9, 0.83.31, 0.83.91, 0.84

Timeline

Official Publish: September 23rd, 2013
Last Modified: September 16th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.