Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-46727: SQL injection through inventory agent request

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory.

CVE
#sql#vulnerability

High

trasher published GHSA-v799-2mp3-wgfr

Dec 13, 2023

Affected versions

>= 10.0.0

Description

Impact

GLPI inventory endpoint can be used to drive a SQL injection attack.

Patches

Upgrade to 10.0.11

Workarounds

Disable native inventory.

For more information

If you have any questions or comments about this advisory, mail us at [email protected].

Credits

This vulnerability was discovered by Nikita Petrov (Positive Technologies).

Severity

CVSS base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907