SQL Injection Vulnerability in GLPI Asset Management Software
CVE-2024-45608
8.8HIGH
Key Information:
- Vendor
- Glpi-project
- Status
- Glpi
- Vendor
- CVE Published:
- 15 November 2024
Summary
An authentication-based SQL injection vulnerability is present in the GLPI asset and IT management software. By altering their preferences, authenticated users can exploit this flaw, potentially allowing unauthorized access to sensitive data. It is important for users operating on versions prior to 10.0.17 to upgrade to this version to mitigate the risk posed by this vulnerability. For more detailed information, refer to the security advisory linked in the references.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published