PT-2020-2710 · Teclib+1 · Glpi+1

Trasher

·

Published

2020-05-05

·

Updated

2020-07-27

·

CVE-2020-11032

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 9.4.6
Description The issue is related to a SQL injection vulnerability in GLPI, which can be exploited by a remote attacker to gain unauthorized access to protected information using specially crafted SQL queries. This vulnerability requires a technician account to be exploited.
Recommendations For versions prior to 9.4.6, update to version 9.4.6 to resolve the issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2358
ALT-PU-2020-2455
BDU:2020-02786
CVE-2020-11032
GHSA-344W-34H9-WWHH

Affected Products

Alt Linux
Glpi