CVE-2013-5696: GLPI-Project GLPI

Medium severity, CVSS 6.8. EPSS: 7.9% chance of exploitation in the next 30 days.

inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.

Affected products

  • GLPI-Project GLPI: up to and including 0.84.1; version 0.5 only; version 0.6 only; version 0.20 only; version 0.21 only; version 0.30 only; …

Published 2013-09-23. Last modified 2026-06-16.