{"id":"CVE-2021-43778","details":"Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.","modified":"2026-04-10T04:39:12.473549Z","published":"2021-11-24T19:15:07.957Z","related":["GHSA-2pjh-h828-wcw9"],"references":[{"type":"WEB","url":"https://github.com/hansmach1ne/CVE-portfolio/tree/main/CVE-2021-43778"},{"type":"ADVISORY","url":"https://github.com/pluginsGLPI/barcode/releases/tag/2.6.1"},{"type":"FIX","url":"https://github.com/pluginsGLPI/barcode/commit/428c3d9adfb446e8492b1c2b7affb3d34072ff46"},{"type":"FIX","url":"https://github.com/pluginsGLPI/barcode/security/advisories/GHSA-2pjh-h828-wcw9"},{"type":"EVIDENCE","url":"https://github.com/hansmach1ne/MyExploits/tree/main/Path%20Traversal%20in%20GLPI%20Barcode%20plugin"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pluginsglpi/barcode","events":[{"introduced":"15f59947af67a6afbab48c76faa4914c07868eff"},{"fixed":"b67fe8fd343c677de3769397f3692903f816730a"},{"fixed":"428c3d9adfb446e8492b1c2b7affb3d34072ff46"}],"database_specific":{"versions":[{"introduced":"2.0"},{"fixed":"2.6.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43778.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}