S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-39211 Scanner

Detects 'Information Disclosure' vulnerability in GLPI affects v. from 9.2 prior to 9.5.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39211
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
glpiby glpi-project
>= 9.2, < 9.5.6
Updated Aug 21, 2026View on NVD →
Detail

GLPI is a widely-used open-source Asset and IT management software package that provides a comprehensive solution for managing software and hardware assets as well as other IT resources. It offers features such as tracking of inventory, managing licenses, monitoring software usage, and managing service contracts. 

Recently, a critical security vulnerability, CVE-2021-39211, was discovered in GLPI versions prior to 9.5.6. This vulnerability exposes GLPI and server information through its telemetry endpoint, which can be used by attackers to gain access to sensitive data. 

When exploited, this vulnerability can lead to a variety of negative impacts, including data breaches, theft of confidential information, and system damage. Attackers can use the information retrieved from the telemetry endpoint to conduct targeted attacks and compromise other systems connected to the GLPI server. 

In order to remain up-to-date with the latest vulnerabilities and security risks affecting their digital assets, users can rely on professional solutions such as s4e.io platform. With its advanced features and capabilities, the platform provides real-time alerts, comprehensive risk assessments, and automated security measures to safeguard users' digital assets from various threats and vulnerabilities. By leveraging its pro features, users can easily and quickly learn about vulnerabilities in their digital assets, and take necessary measures to address them before they turn into catastrophic security incidents.

 

REFERENCES

Solution Advice

Fortunately, there are several measures that users can take to protect against this vulnerability. These precautionary measures include: 

  • Updating GLPI to version 9.5.6 or newer 
  • Removing the telemetry.php file 
  • Securing the server and ensuring proper access controls are in place 
  • Monitoring network traffic for suspicious activity 
  • Keeping track of all changes made to the server and performing regular backups 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-39211 scanner - Information Disclosure vulnerability in GLPI | S4E