SQL Injection Vulnerability in GLPI Asset Management Software
CVE-2024-45608

8.8HIGH

Key Information:

Vendor
Glpi-project
Status
Glpi
Vendor
CVE Published:
15 November 2024

Summary

An authentication-based SQL injection vulnerability is present in the GLPI asset and IT management software. By altering their preferences, authenticated users can exploit this flaw, potentially allowing unauthorized access to sensitive data. It is important for users operating on versions prior to 10.0.17 to upgrade to this version to mitigate the risk posed by this vulnerability. For more detailed information, refer to the security advisory linked in the references.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.