PT-2020-4343 · Teclib+1 · Glpi+1
Trasher
·
Published
2020-07-17
·
Updated
2024-05-22
·
CVE-2020-15108
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
GLPI versions prior to 9.5.1
Description:
The issue is related to the Clone feature in the GLPI system, which is vulnerable due to incorrect neutralization of special elements used in SQL queries. This allows a remote attacker to execute arbitrary SQL commands. The problem affects all usages of the Clone functionality.
Recommendations:
For versions prior to 9.5.1, update to version 9.5.1 to resolve the issue. As a temporary workaround, consider restricting the use of the Clone feature until the update is applied.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Glpi