CVE-2022-39323: SQL Injection on REST API in GLPI
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST usertoken. This issue has been patched, please upgrade to version 10.0.4. As a workaround, disable login with usertoken on API Rest.
Affected Software
Event History
Frequently Asked Questions
What is GLPI?
GLPI stands for Gestionnaire Libre de Parc Informatique. It is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking, and software auditing.
What is the vulnerability ID for this GLPI vulnerability?
The vulnerability ID for this GLPI vulnerability is CVE-2022-39323.
What is the severity of CVE-2022-39323?
The severity of CVE-2022-39323 is critical with a CVSS score of 9.8.
What is the affected software version range for CVE-2022-39323?
The affected software version range for CVE-2022-39323 is GLPI version 9.1 to 10.0.4.
How do I fix CVE-2022-39323?
To fix CVE-2022-39323, please upgrade GLPI to the patched version.