CVE-2023-43813: glpi Authenticated SQL Injection
Published Dec 13, 2023
·Updated
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. Version 10.0.11 contains a patch for the issue.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=10.0.0<10.0.11
Remediation
Event History
Dec 13, 2023
CVE Published
06:17 PM
Data Sourced
06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-43813?
CVE-2023-43813 is classified as a high severity SQL injection vulnerability affecting GLPI versions 10.0.0 to 10.0.10.
2
How do I fix CVE-2023-43813?
To fix CVE-2023-43813, upgrade GLPI to version 10.0.11 or later.
3
What versions are affected by CVE-2023-43813?
CVE-2023-43813 impacts GLPI versions from 10.0.0 up to, but not including, 10.0.11.
4
Can CVE-2023-43813 be exploited remotely?
Yes, CVE-2023-43813 can be exploited remotely through the saved search feature in GLPI.
5
What type of vulnerability is CVE-2023-43813?
CVE-2023-43813 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL queries.