CVE-2023-46727: GLPI SQL injection through inventory agent request
Published Dec 13, 2023
·Updated
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=10.0.0<10.0.11
Remediation
Event History
Dec 13, 2023
CVE Published
06:26 PM
Data Sourced
06:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46727?
CVE-2023-46727 has been classified as a high-severity vulnerability due to the potential for a SQL injection attack.
2
How do I fix CVE-2023-46727?
To fix CVE-2023-46727, update your GLPI installation to version 10.0.11 or higher.
3
What versions of GLPI are affected by CVE-2023-46727?
CVE-2023-46727 affects GLPI versions from 10.0.0 to 10.0.10.
4
Can I disable a feature to mitigate CVE-2023-46727?
Yes, as a temporary workaround, you can disable the native inventory feature in GLPI to mitigate CVE-2023-46727.
5
What type of vulnerability is CVE-2023-46727?
CVE-2023-46727 is categorized as a SQL injection vulnerability affecting GLPI's inventory endpoint.