CVE-2015-7685: GLPI-Project GLPI

Medium severity, CVSS 4.0. EPSS: 1.7% chance of exploitation in the next 30 days.

GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.

Affected products

Published 2015-10-05. Last modified 2026-06-17.