CVE-2021-44617: SQL Injection
Published Mar 28, 2022
·Updated
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
Affected Software
1 affected component
GLPI-PROJECT GLPI=9.4.6
Event History
Mar 28, 2022
CVE Published
via MITRE·01:08 AM
Data Sourced
via MITRE·01:08 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-44617?
CVE-2021-44617 is classified as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2021-44617?
To mitigate CVE-2021-44617, upgrade GLPI from version 9.4.6 to a version that has patched this vulnerability.
3
What impact does CVE-2021-44617 have on GLPI users?
CVE-2021-44617 allows attackers to execute arbitrary SQL queries, potentially leading to data leaks or data manipulation.
4
Which version of GLPI is affected by CVE-2021-44617?
CVE-2021-44617 specifically affects GLPI version 9.4.6.
5
Where is the SQL Injection vulnerability located in CVE-2021-44617?
The SQL Injection vulnerability in CVE-2021-44617 is found in the idu parameter of the plugins/ramo/ramoapirest.php/getOutdated endpoint.