CVE Vulnerabilities

CVE-2014-5032

Published: Apr 14, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.

Affected Software

NameVendorStart VersionEnd Version
GlpiGlpi-project*0.84.6 (including)
GlpiUbuntulucid*
GlpiUbuntuprecise*
GlpiUbuntutrusty*
GlpiUbuntuupstream*
GlpiUbuntuutopic*
GlpiUbuntuvivid*
GlpiUbuntuwily*

References