First published: Tue Jun 28 2022(Updated: )
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI-PROJECT GLPI | >=10.0.0<10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
GLPI is a Free Asset and IT Management Software package, used for data center management, ITIL Service Desk, licenses tracking, and software auditing.
The vulnerability ID for GLPI is CVE-2022-31056.
The severity of CVE-2022-31056 is critical with a CVSS score of 9.8.
In affected versions, all assistance forms (Ticket/Change/Problem) in GLPI permit SQL injection on the actor fields.
CVE-2022-31056 has been resolved in version 10.0.2 of GLPI, so upgrading to this version will fix the vulnerability.