PT-2023-8845 · Glpi+2 · Glpi+2

Cyber-Brent

·

Published

2023-12-13

·

Updated

2024-10-08

·

CVE-2023-43813

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions 10.0.0 through 10.0.10
Description The issue is related to the saved search feature in GLPI, which can be used to perform a SQL injection. This allows a remote attacker to execute arbitrary code. The vulnerability is due to the lack of protection of the SQL query structure.
Recommendations For versions 10.0.0 through 10.0.10, update to version 10.0.11, which contains a patch for the issue. As a temporary workaround, consider restricting access to the saved search feature until the patch is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8061
ALT-PU-2023-8087
ALT-PU-2024-8030
BDU:2024-02266
CVE-2023-43813
GHSA-94C3-FW5R-3362

Affected Products

Alt Linux
Glpi
Red Os