First published: Fri Jan 28 2022(Updated: )
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | <9.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21720 is considered a high severity vulnerability due to its potential for unauthorized data access via SQL injection.
To fix CVE-2022-21720, upgrade to GLPI version 9.5.7 or later where the vulnerability is patched.
CVE-2022-21720 is an SQL injection vulnerability that allows an entity administrator to access restricted data.
CVE-2022-21720 affects all versions of GLPI prior to 9.5.7.
Yes, as a temporary workaround, you can disable the 'Entities' update right to mitigate the risk associated with CVE-2022-21720.