PT-2024-10109 · Glpi+2 · Glpi+2

Bkatapi

·

Published

2024-11-15

·

Updated

2025-08-13

·

CVE-2024-45608

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.17
Description The issue is related to a lack of protection against SQL injection attacks. An authenticated user can perform a SQL injection by changing their preferences. This could allow a remote attacker to execute SQL injections.
Recommendations For versions prior to 10.0.17, upgrade to version 10.0.17 to resolve the issue. As a temporary workaround, consider restricting access to preference changes for authenticated users until the upgrade is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-1277
BDU:2025-00333
CVE-2024-45608
GHSA-67P8-V79J-JP86

Affected Products

Alt Linux
Glpi
Red Os