First published: Fri Nov 15 2024(Updated: )
GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | >=9.5.0<10.0.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45608 is categorized as a medium severity vulnerability due to the potential for SQL injection.
To fix CVE-2024-45608, you should upgrade your GLPI installation to version 10.0.17 or later.
CVE-2024-45608 affects users of GLPI versions from 9.5.0 up to but not including 10.0.17.
CVE-2024-45608 enables authenticated users to perform a SQL injection attack by altering their preferences.
CVE-2024-45608 is a local vulnerability since it requires authentication to exploit.