← Back to CVE List

CVE-2021-39210

Published: 2021-09-15T17:15Z
Last Modified: 2024-11-21T06:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt