GLPI Fixes SQL Injection Vulnerability in Map Search
CVE-2024-31456
6.5MEDIUM
What is CVE-2024-31456?
GLPI, an open-source asset and IT management software, is susceptible to a SQL injection vulnerability that affects versions prior to 10.0.15. The flaw enables authenticated users to execute malicious SQL queries through the map search functionality, potentially leading to unauthorized data access or manipulation. It is crucial for users of GLPI to upgrade to the fixed version 10.0.15 to mitigate this risk and ensure the integrity of their data management operations.
Affected Version(s)
glpi < 10.0.15