GLPI vulnerable to SQL injection through Computer Virtual Machine information
CVE-2023-36808
Key Information:
- Vendor
Glpi-project
- Status
- Vendor
- CVE Published:
- 5 July 2023
Badges
What is CVE-2023-36808?
GLPI, a widely used asset and IT management software, is susceptible to SQL injection due to vulnerabilities in its Computer Virtual Machine form and inventory request feature. This flaw allows attackers to manipulate database queries, potentially compromising sensitive data. Users are encouraged to upgrade to version 10.0.8, which provides a patch for this vulnerability. As a temporary measure, disabling native inventory can help mitigate risks until an upgrade is completed.
Affected Version(s)
glpi >= 0.80, < 10.0.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
44% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
