First published: Fri Mar 15 2024(Updated: )
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | <10.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27756 has been classified as a medium severity vulnerability.
To fix CVE-2024-27756, update GLPI to version 10.0.13 or later.
CVE-2024-27756 allows attackers to execute malicious commands through CSV injection via crafted asset titles.
CVE-2024-27756 affects users of GLPI versions prior to 10.0.13.
CVE-2024-27756 is a vulnerability that enables CSV injection due to improperly sanitized inputs in asset titles.