← Vulnerability feed

Vulnerability record · CVE-2020-15175 · published 7 October 2020

CVE-2020-15175: GLPI pluginimage.send.php path traversal deletes .htaccess, exposes files

Glpi Project · Glpi

GLPI before 9.5.2 exposes the pluginimage.send.php endpoint, which accepts user-supplied parameters that can be crafted to delete the .htaccess file protecting the files directory. Once that file is gone, any user can read all files and folders under /files/, including session data and logs. The flaw is patched in 9.5.2.

9.1 CVSS 3.1 Critical EPSS 72% · top 0.6% CWE-552 · CWE-552
9.1CVSS 3.1 base score, v2 6.4
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becomes able to read all the files and folders contained in “/files/”. Some of the sensitive information that is compromised are the user sessions, logs, and more. An attacker would be able to get the Administrators session token and use that to authenticate. The issue is patched in version 9.5.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.1 with no authentication or interaction required and a high EPSS percentile, and successful exploitation yields administrator session tokens.

What it is

GLPI before 9.5.2 exposes the pluginimage.send.php endpoint, which accepts user-supplied parameters that can be crafted to delete the .htaccess file protecting the files directory. Once that file is gone, any user can read all files and folders under /files/, including session data and logs. The flaw is patched in 9.5.2.

Impact

An attacker can read sensitive files under /files/, including user sessions and logs, and can obtain an administrator's session token to authenticate as that administrator.

Attack surface

Reachable over the network through the pluginimage.send.php endpoint with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.7155 (99.4th percentile), indicating elevated likelihood of exploitation; references are patch and advisory only, with no public exploit tag.

What to do

  • Upgrade GLPI to version 9.5.2 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict or block access to pluginimage.send.php at the web server or reverse proxy.
  • Verify the .htaccess file in the files directory exists and is intact, and restore it if missing.
  • Move or harden the files directory so it is not web-accessible, and confirm directory listing and direct file access are denied.
  • Rotate session tokens and credentials for administrative accounts as a precaution if exposure is suspected.

Detection

  • Monitor web logs for requests to pluginimage.send.php with unusual or crafted parameters.
  • Alert on deletion or modification of .htaccess files in the GLPI files directory.
  • Watch for direct HTTP requests to paths under /files/ that would previously have been blocked.
  • Review authentication logs for administrator sessions originating from unexpected sources or tokens.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15175 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2025-24799GLPI unauthenticated SQL injection in inventory endpointGLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issu…EPSS 87%analysed9.8CVE-2023-46727GLPI inventory endpoint SQL injectionGLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authent…EPSS 68%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 1.0%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-15175), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.