GLPI Fixes SQL Injection Vulnerability in Map Search
CVE-2024-31456
6.5MEDIUM
Key Information:
- Vendor
- Glpi-project
- Status
- Glpi
- Vendor
- CVE Published:
- 7 May 2024
Summary
GLPI, an open-source asset and IT management software, is susceptible to a SQL injection vulnerability that affects versions prior to 10.0.15. The flaw enables authenticated users to execute malicious SQL queries through the map search functionality, potentially leading to unauthorized data access or manipulation. It is crucial for users of GLPI to upgrade to the fixed version 10.0.15 to mitigate this risk and ensure the integrity of their data management operations.
Affected Version(s)
glpi < 10.0.15
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved