CVE-2024-45600: Fields GLPI plugin has an Authenticated SQL Injection
Published Dec 26, 2024
·Updated
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.
Affected Software
1 affected component
GLPI Fields plugin<1.21.13
Event History
Dec 26, 2024
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45600?
CVE-2024-45600 has been classified as a critical vulnerability due to the potential for SQL injection allowing unauthorized database access.
2
How do I fix CVE-2024-45600?
To fix CVE-2024-45600, upgrade the GLPI Fields plugin to version 1.21.13 or later.
3
Who is affected by CVE-2024-45600?
Authenticated users of the GLPI Fields plugin prior to version 1.21.13 are affected by CVE-2024-45600.
4
What type of vulnerability is CVE-2024-45600?
CVE-2024-45600 is a SQL injection vulnerability that can be exploited by an authenticated user.
5
What software does CVE-2024-45600 impact?
CVE-2024-45600 specifically impacts the GLPI Fields plugin versions earlier than 1.21.13.