Vulnerability record · CVE-2020-15175 · published 7 October 2020
CVE-2020-15175: GLPI pluginimage.send.php path traversal deletes .htaccess, exposes files
Glpi Project · Glpi
GLPI before 9.5.2 exposes the pluginimage.send.php endpoint, which accepts user-supplied parameters that can be crafted to delete the .htaccess file protecting the files directory. Once that file is gone, any user can read all files and folders under /files/, including session data and logs. The flaw is patched in 9.5.2.
Description
In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becomes able to read all the files and folders contained in “/files/”. Some of the sensitive information that is compromised are the user sessions, logs, and more. An attacker would be able to get the Administrators session token and use that to authenticate. The issue is patched in version 9.5.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with no authentication or interaction required and a high EPSS percentile, and successful exploitation yields administrator session tokens.
What it is
GLPI before 9.5.2 exposes the pluginimage.send.php endpoint, which accepts user-supplied parameters that can be crafted to delete the .htaccess file protecting the files directory. Once that file is gone, any user can read all files and folders under /files/, including session data and logs. The flaw is patched in 9.5.2.
Impact
An attacker can read sensitive files under /files/, including user sessions and logs, and can obtain an administrator's session token to authenticate as that administrator.
Attack surface
Reachable over the network through the pluginimage.send.php endpoint with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.7155 (99.4th percentile), indicating elevated likelihood of exploitation; references are patch and advisory only, with no public exploit tag.
What to do
- Upgrade GLPI to version 9.5.2 or later, which contains the fix.
- If immediate upgrade is not possible, restrict or block access to pluginimage.send.php at the web server or reverse proxy.
- Verify the .htaccess file in the files directory exists and is intact, and restore it if missing.
- Move or harden the files directory so it is not web-accessible, and confirm directory listing and direct file access are denied.
- Rotate session tokens and credentials for administrative accounts as a precaution if exposure is suspected.
Detection
- Monitor web logs for requests to pluginimage.send.php with unusual or crafted parameters.
- Alert on deletion or modification of .htaccess files in the GLPI files directory.
- Watch for direct HTTP requests to paths under /files/ that would previously have been blocked.
- Review authentication logs for administrator sessions originating from unexpected sources or tokens.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/glpi-project/glpi/commit/6ca9a0e77299a755c356d758344a23278df67f65 | PatchThird Party Advisory |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-rm52-jx9h-rwcp | Third Party Advisory |
| https://github.com/glpi-project/glpi/commit/6ca9a0e77299a755c356d758344a23278df67f65 | PatchThird Party Advisory |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-rm52-jx9h-rwcp | Third Party Advisory |
Track CVE-2020-15175 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15175), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.