GLPI Fixes SQL Injection Vulnerability in Map Search
CVE-2024-31456

6.5MEDIUM

Key Information:

Vendor
Glpi-project
Status
Glpi
Vendor
CVE Published:
7 May 2024

Summary

GLPI, an open-source asset and IT management software, is susceptible to a SQL injection vulnerability that affects versions prior to 10.0.15. The flaw enables authenticated users to execute malicious SQL queries through the map search functionality, potentially leading to unauthorized data access or manipulation. It is crucial for users of GLPI to upgrade to the fixed version 10.0.15 to mitigate this risk and ensure the integrity of their data management operations.

Affected Version(s)

glpi < 10.0.15

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.