PT-2023-8845 · Glpi+2 · Glpi+2

Cyber-Brent

·

Publicado

2023-12-13

·

Atualizado

2024-10-08

·

CVE-2023-43813

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions 10.0.0 through 10.0.10
Description The issue is related to the saved search feature in GLPI, which can be used to perform a SQL injection. This allows a remote attacker to execute arbitrary code. The vulnerability is due to the lack of protection of the SQL query structure.
Recommendations For versions 10.0.0 through 10.0.10, update to version 10.0.11, which contains a patch for the issue. As a temporary workaround, consider restricting access to the saved search feature until the patch is applied.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-8061
ALT-PU-2023-8087
ALT-PU-2024-8030
BDU:2024-02266
CVE-2023-43813
GHSA-94C3-FW5R-3362

Produtos afetados

Alt Linux
Glpi
Red Os