CVE-2024-40638: GLPI allows account takeover via SQL Injection in AJAX scripts
Published Nov 15, 2024
·Updated
GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=0.85<10.0.17
Event History
Nov 15, 2024
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-40638?
CVE-2024-40638 is classified as a critical vulnerability due to its potential for account takeover through SQL injection.
2
How do I fix CVE-2024-40638?
To remediate CVE-2024-40638, users should upgrade GLPI to version 10.0.17 or later.
3
What type of vulnerability is CVE-2024-40638?
CVE-2024-40638 is an SQL injection vulnerability that allows authenticated users to manipulate account data.
4
Who is affected by CVE-2024-40638?
Users of GLPI versions prior to 10.0.17 are vulnerable to CVE-2024-40638.
5
What can an attacker do with CVE-2024-40638?
An attacker exploiting CVE-2024-40638 can alter user account data and potentially take control of other users' accounts.