PT-2022-1462 · Glpi+2 · Glpi+2

Bull53Y3Fl1Nch

·

Published

2022-01-27

·

Updated

2024-05-22

·

CVE-2022-21720

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 9.5.7
Description The issue is related to a lack of protection against SQL query structure exploitation, allowing a remote attacker to execute arbitrary SQL queries. An entity administrator can retrieve normally inaccessible data via SQL injection.
Recommendations For versions prior to 9.5.7, update to version 9.5.7 to resolve the issue. As a temporary workaround, consider disabling the Entities update right to prevent exploitation of this vulnerability.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1463
ALT-PU-2022-1514
ALT-PU-2022-1526
ALT-PU-2022-2614
ALT-PU-2022-2624
ALT-PU-2022-2665
ALT-PU-2023-7633
ALT-PU-2024-8030
ALT-PU-2024-8094
BDU:2022-00591
CVE-2022-21720
GHSA-5HG4-R64R-RF83

Affected Products

Alt Linux
Glpi
Red Os