First published: Wed Dec 13 2023(Updated: )
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. Version 10.0.11 contains a patch for the issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | >=10.0.0<10.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43813 is classified as a high severity SQL injection vulnerability affecting GLPI versions 10.0.0 to 10.0.10.
To fix CVE-2023-43813, upgrade GLPI to version 10.0.11 or later.
CVE-2023-43813 impacts GLPI versions from 10.0.0 up to, but not including, 10.0.11.
Yes, CVE-2023-43813 can be exploited remotely through the saved search feature in GLPI.
CVE-2023-43813 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL queries.