CVE-2024-31456: GLPI contains an authenticated SQL injection
Published May 7, 2024
·Updated
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. This vulnerability is fixed in 10.0.15.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=9.3.0<10.0.15
Remediation
Event History
May 7, 2024
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31456?
CVE-2024-31456 has a high severity due to its potential impact on data integrity and confidentiality through SQL injection.
2
How do I fix CVE-2024-31456?
To fix CVE-2024-31456, upgrade GLPI to version 10.0.15 or later.
3
What versions of GLPI are affected by CVE-2024-31456?
GLPI versions prior to 10.0.15, specifically from 9.3.0 to 10.0.14, are affected by CVE-2024-31456.
4
What type of vulnerability is CVE-2024-31456?
CVE-2024-31456 is a SQL injection vulnerability that can be exploited by authenticated users.
5
Is authentication required to exploit CVE-2024-31456?
Yes, exploitation of CVE-2024-31456 requires the attacker to be an authenticated user.