PT-2022-7405 · Glpi+2 · Glpi+2
M00Nback
+1
·
Published
2022-09-14
·
Updated
2024-07-26
·
CVE-2022-35947
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GLPI versions prior to 10.0.3
Description
The issue is related to a SQL injection attack that could allow an attacker to simulate an arbitrary user login. This is due to the lack of protection measures for the SQL query structure. The vulnerability can be exploited remotely, potentially allowing an attacker to scan server ports or services and conduct SQL injection attacks.
Recommendations
For versions prior to 10.0.3, upgrade to version 10.0.3 to resolve the issue.
As a temporary workaround for users unable to upgrade, disable the
Enable login with external token API configuration.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Glpi
Red Os