PT-2024-10112 · Glpi+2 · Glpi+2

Tpierru

·

Published

2024-11-15

·

Updated

2025-08-13

·

CVE-2024-41679

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.17
Description The issue is related to a SQL injection vulnerability in the ticket form of GLPI, a free asset and IT management software package. An authenticated user can exploit this vulnerability, potentially allowing a remote attacker to perform SQL injections. The vulnerability is due to a lack of protection measures for the SQL query structure.
Recommendations For versions prior to 10.0.17, upgrade to version 10.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the ticket form until the upgrade is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-1277
BDU:2025-00336
CVE-2024-41679
GHSA-HQ9Q-JFHP-QQGM

Affected Products

Alt Linux
Glpi
Red Os