First published: Mon Mar 28 2022(Updated: )
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | =9.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44617 is classified as a high severity SQL Injection vulnerability.
To mitigate CVE-2021-44617, upgrade GLPI from version 9.4.6 to a version that has patched this vulnerability.
CVE-2021-44617 allows attackers to execute arbitrary SQL queries, potentially leading to data leaks or data manipulation.
CVE-2021-44617 specifically affects GLPI version 9.4.6.
The SQL Injection vulnerability in CVE-2021-44617 is found in the idu parameter of the plugins/ramo/ramoapirest.php/getOutdated endpoint.