CRITICAL🇵🇱 Wersja polska

CVE-2021-43779

CVSS 9.9v3.1pub. 2022-01-05upd. 2025-09-08

GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
  • Teclib Edition Addressing

    APP
    Teclib-Edition
    < 2.9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2026-23489CRITICAL9.1PL ✓same vendor

RCE przez tworzenie dropdownów w pluginie Fields dla GLPI

CVE-2019-12723CRITICAL9.8PL ✓same vendor

SQL Injection w Teclib Fields plugin dla GLPI — dostęp bez uwierzytelnienia

CVE-2019-10232CRITICAL9.8PL ✓same vendor

SQL injection w GLPI via parametr 'cycle' w skrypcie unlock_tasks.php

CVE-2019-10231CRITICAL9.8PL ✓same vendor

Pominięcie uwierzytelnienia w GLPI przez PHP type juggling

CVE-2026-22248HIGH8.0same vendor

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, lice...