PT-2020-4300 · Teclib+1 · Glpi+1

Hightrasher

·

Published

2020-10-07

·

Updated

2024-05-22

·

CVE-2020-15176

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: GLPI versions prior to 9.5.2
Description: The issue is related to the incorrect neutralization of special elements used in SQL commands, which can allow a remote attacker to execute arbitrary SQL queries to the database in the target system by sending a specially crafted request to the vulnerable application. This can lead to the exfiltration of sensitive information, including passwords, reset tokens, and personal details.
Recommendations: For versions prior to 9.5.2, update to version 9.5.2 or later to resolve the issue. As a temporary workaround, consider restricting input that gets put into SQL queries to prevent SQL Injection. Avoid using back ticks in input that gets put into SQL queries until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3130
ALT-PU-2020-3162
ALT-PU-2024-8094
BDU:2020-04793
CVE-2020-15176
GHSA-X93W-64X9-58QW

Affected Products

Alt Linux
Glpi