GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.
https://forge.indepnet.net/issues/4984
http://www.mandriva.com/security/advisories?name=MDVSA-2015:167
http://www.glpi-project.org/spip.php?page=annonce&id_breve=325