First published: Tue May 07 2024(Updated: )
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. This vulnerability is fixed in 10.0.15.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | >=9.3.0<10.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31456 has a high severity due to its potential impact on data integrity and confidentiality through SQL injection.
To fix CVE-2024-31456, upgrade GLPI to version 10.0.15 or later.
GLPI versions prior to 10.0.15, specifically from 9.3.0 to 10.0.14, are affected by CVE-2024-31456.
CVE-2024-31456 is a SQL injection vulnerability that can be exploited by authenticated users.
Yes, exploitation of CVE-2024-31456 requires the attacker to be an authenticated user.