CVE-2024-27756: Code Injection
Published Mar 15, 2024
·Updated
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
Affected Software
2 affected components
GLPI GLPI<10.0.12
GLPI-PROJECT GLPI<=10.0.12
Event History
Mar 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27756?
CVE-2024-27756 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-27756?
To fix CVE-2024-27756, update GLPI to version 10.0.13 or later.
3
What are the potential impacts of CVE-2024-27756?
CVE-2024-27756 allows attackers to execute malicious commands through CSV injection via crafted asset titles.
4
Who is affected by CVE-2024-27756?
CVE-2024-27756 affects users of GLPI versions prior to 10.0.13.
5
What is the nature of the vulnerability in CVE-2024-27756?
CVE-2024-27756 is a vulnerability that enables CSV injection due to improperly sanitized inputs in asset titles.