CVE-2024-45608: GLPI has an Authenticated SQL Injection
Published Nov 15, 2024
·Updated
GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=9.5.0<10.0.17
Event History
Nov 15, 2024
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45608?
CVE-2024-45608 is categorized as a medium severity vulnerability due to the potential for SQL injection.
2
How do I fix CVE-2024-45608?
To fix CVE-2024-45608, you should upgrade your GLPI installation to version 10.0.17 or later.
3
Who is affected by CVE-2024-45608?
CVE-2024-45608 affects users of GLPI versions from 9.5.0 up to but not including 10.0.17.
4
What kind of attack does CVE-2024-45608 enable?
CVE-2024-45608 enables authenticated users to perform a SQL injection attack by altering their preferences.
5
Is CVE-2024-45608 a local or remote vulnerability?
CVE-2024-45608 is a local vulnerability since it requires authentication to exploit.