First published: Wed Oct 07 2020(Updated: )
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker is able to exfiltrate sensitive information like passwords, reset tokens, personal details, and more. The issue is patched in version 9.5.2
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Teclib GLPI | <9.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15176 has been classified as a high-severity vulnerability due to its potential for SQL injection and sensitive data exfiltration.
To fix CVE-2020-15176, upgrade GLPI to version 9.5.2 or later where the vulnerability has been addressed.
CVE-2020-15176 is an SQL injection vulnerability that allows attackers to manipulate SQL queries and access sensitive information.
GLPI versions prior to 9.5.2 are affected by CVE-2020-15176 and are vulnerable to SQL injection.
Attackers leveraging CVE-2020-15176 can exploit the vulnerability to exfiltrate sensitive information, including user passwords.