GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 18 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-18T19:58:12.082Z
Reserved: 2023-06-20T14:02:45.592Z
Link: CVE-2023-35924
Updated: 2024-08-02T16:37:40.529Z
Status : Modified
Published: 2023-07-05T20:15:10.483
Modified: 2024-11-21T08:08:59.213
Link: CVE-2023-35924
No data.
OpenCVE Enrichment
No data.
Weaknesses