{"id":"UBUNTU-CVE-2013-5696","details":"inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.","modified":"2025-07-16T07:31:25.895886Z","published":"2013-09-23T03:49:00Z","withdrawn":"2025-07-18T16:42:56Z","upstream":["CVE-2013-5696"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-5696"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2013/09/20/5"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-5696"}],"affected":[{"package":{"name":"glpi","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/glpi@0.84.2-1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.84.2-1"}]}],"versions":["0.83.91-3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"0.84.2-1","binary_name":"glpi"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-5696.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}