PT-2020-4343 · Teclib+1 · Glpi+1

Trasher

·

Published

2020-07-17

·

Updated

2024-05-22

·

CVE-2020-15108

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions: GLPI versions prior to 9.5.1
Description: The issue is related to the Clone feature in the GLPI system, which is vulnerable due to incorrect neutralization of special elements used in SQL queries. This allows a remote attacker to execute arbitrary SQL commands. The problem affects all usages of the Clone functionality.
Recommendations: For versions prior to 9.5.1, update to version 9.5.1 to resolve the issue. As a temporary workaround, consider restricting the use of the Clone feature until the update is applied.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3130
ALT-PU-2020-3162
ALT-PU-2024-8094
BDU:2020-04845
CVE-2020-15108
GHSA-QV6W-68GQ-WX2V

Affected Products

Alt Linux
Glpi