CVE-2022-31082: SQL Injection via package deployment tasks in glpi-inventory-plugin
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection can be made using package deployment tasks. This issue has been resolved in version 1.0.2. Users are advised to upgrade. Users unable to upgrade should delete the front/deploypackage.public.php file if they are not using the deploy tasks feature.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31082?
CVE-2022-31082 has been assigned a medium severity rating due to the potential for SQL injection.
How do I fix CVE-2022-31082?
To fix CVE-2022-31082, upgrade the GLPI Inventory Plugin to version 1.0.2 or later.
Which versions of GLPI are affected by CVE-2022-31082?
CVE-2022-31082 affects all versions of the GLPI Inventory Plugin prior to 1.0.2.
What type of vulnerability is CVE-2022-31082?
CVE-2022-31082 is classified as a SQL injection vulnerability.
Can CVE-2022-31082 lead to data breaches?
Yes, CVE-2022-31082 can potentially lead to unauthorized access to sensitive data through SQL injection.