Arbitrary Code Injection Affecting glpi package, versions *


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
15.52% (95th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1604-GLPI-1147760
  • published1 Jun 2025
  • disclosed12 May 2020

Introduced: 12 May 2020

CVE-2020-11060  (opens in a new tab)
CWE-74  (opens in a new tab)

How to fix?

There is no fixed version for Ubuntu:16.04 glpi.

NVD Description

Note: Versions mentioned in the description apply only to the upstream glpi package and not the glpi package as distributed by Ubuntu. See How to fix? for Ubuntu:16.04 relevant fixed versions and status.

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, the attack is only conceivable by an account having Maintenance privileges and the right to add WIFI networks. This is fixed in version 9.4.6.

CVSS Base Scores

version 3.1