Description
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 19 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-19T14:17:31.449Z
Reserved: 2023-10-25T14:30:33.751Z
Link: CVE-2023-46727
Updated: 2024-08-02T20:53:21.207Z
Status : Modified
Published: 2023-12-13T19:15:08.047
Modified: 2024-11-21T08:29:10.210
Link: CVE-2023-46727
No data.
OpenCVE Enrichment
No data.
Weaknesses