21. 09. 2026 Cecilia Marchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (GLPI)

Important: GLPI security update

Type/Severity

NetEye Product Security has rated this update as having a high security impact.

Topic

An update for the glpi packages is now available for NetEye 4.

Security Fix for NetEye 4.49

  • glpi-11.0.9_neteye1.20.3-2
  • glpi-autosetup-11.0.9_neteye1.20.3-2
  • glpi-configurator-11.0.9_neteye1.20.3-2

Summary

This is the list of vulnerabilities patched in this update:

  • XSS via form illustration import
  • Stored XSS in ticket actors
  • MFA bypass by another GLPI user
  • Stored XSS via asset name
  • Stored XSS in network equipement models
  • Upload of malicious page on the web-server
  • Unauthenticated SQL injection in planning feature
  • Unexpected X509 authentication success with unverified certificated
  • Race condition in marketplace allowing malicious plugin installation
  • Arbitrary files deletion during documents creation
  • Unexpected access to followups/tasks/solutions generated from templates
  • Unauthorized visibility expansion of knowbase items, reminders and RSS feed

For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section in the User Guide.

Affected Products

All NetEye 4.x versions

References

Cecilia Marchi

Cecilia Marchi

Author

Cecilia Marchi

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive