CVE-2023-36808: GLPI vulnerable to SQL injection through Computer Virtual Machine information
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.8 - Configuration
As a workaround, disable native inventory to mitigate the SQL injection path via the Computer Virtual Machine form and GLPI inventory requests (applies to versions starting in 0.80 and prior to 10.0.8).
GLPI Native inventory = disabled
Event History
Frequently Asked Questions
What is CVE-2023-36808?
CVE-2023-36808 is a vulnerability in GLPI, a free asset and IT management software package, that allows for a SQL injection attack.
What is the severity of CVE-2023-36808?
The severity of CVE-2023-36808 is critical, with a severity value of 9.8.
How does CVE-2023-36808 work?
CVE-2023-36808 can be exploited through the Computer Virtual Machine form and GLPI inventory request to perform a SQL injection attack.
Is there a patch for CVE-2023-36808?
Yes, version 10.0.8 of GLPI has a patch for CVE-2023-36808.
How can I mitigate the risk of CVE-2023-36808?
As a workaround, you can disable the native inventory module in GLPI.