Information disclosure in GLPI - CVE-2022-31143
Published: September 14, 2022 / Updated: May 4, 2026
GLPI
glpi-project
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the login page error handling when handling login errors. A remote attacker can trigger a login page error to disclose sensitive information.
Passwords are not exposed.