Glpi · Glpi · CVE-2023-51446
**Name of the Vulnerable Software and Affected Versions**
GLPI versions prior to 10.0.12
**Description**
The issue is related to LDAP injection when authentication is made against a LDAP server. This can be exploited by a remote attacker to perform LDAP injection using the authentication form. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
**Recommendations**
For versions prior to 10.0.12, upgrade to version 10.0.12 to resolve the issue. As a temporary workaround, consider restricting access to the LDAP authentication form until the upgrade is applied. Avoid using the authentication form against a LDAP server until the issue is resolved.