PT-2020-4343 · Teclib+1 · Glpi+1

·

CVE-2020-15108

·

Published

2020-07-17

·

Updated

2024-05-22

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions: GLPI versions prior to 9.5.1
Description: The issue is related to the Clone feature in the GLPI system, which is vulnerable due to incorrect neutralization of special elements used in SQL queries. This allows a remote attacker to execute arbitrary SQL commands. The problem affects all usages of the Clone functionality.
Recommendations: For versions prior to 9.5.1, update to version 9.5.1 to resolve the issue. As a temporary workaround, consider restricting the use of the Clone feature until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3130
ALT-PU-2020-3162
ALT-PU-2024-8094
BDU:2020-04845
CVE-2020-15108
GHSA-QV6W-68GQ-WX2V

Affected Products

Alt Linux
Glpi