CVE-2016-7507: GLPI-Project GLPI

High severity, CVSS 8.0. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.

Affected products

Published 2017-07-19. Last modified 2026-06-17.