PT-2022-12187 · Unknown+2 · Ramo Plugin+2

Published

2020-10-27

·

Updated

2024-05-22

·

CVE-2021-44617

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI version 9.4.6
Description A SQL Injection issue exists in the Ramo plugin for GLPI via the idu parameter in the /plugins/ramo/ramoapirest.php/getOutdated API endpoint.
Recommendations For GLPI version 9.4.6, consider restricting access to the ramoapirest.php file or the getOutdated function until a patch is available. Avoid using the idu parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3130
ALT-PU-2020-3162
ALT-PU-2024-8094
CVE-2021-44617

Affected Products

Alt Linux
Glpi
Ramo Plugin