CVE-2022-31056: SQL injection with _actor parameter in GLPI
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.
Affected Software
Event History
Frequently Asked Questions
What is GLPI?
GLPI is a Free Asset and IT Management Software package, used for data center management, ITIL Service Desk, licenses tracking, and software auditing.
What is the vulnerability ID for GLPI?
The vulnerability ID for GLPI is CVE-2022-31056.
What is the severity of CVE-2022-31056?
The severity of CVE-2022-31056 is critical with a CVSS score of 9.8.
How does CVE-2022-31056 affect GLPI?
In affected versions, all assistance forms (Ticket/Change/Problem) in GLPI permit SQL injection on the actor fields.
How can I fix CVE-2022-31056 in GLPI?
CVE-2022-31056 has been resolved in version 10.0.2 of GLPI, so upgrading to this version will fix the vulnerability.