Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Dec 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13. | |
Title | Fields GLPI plugin has an Authenticated SQL Injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-26T21:27:01.168Z
Updated: 2024-12-26T21:27:01.168Z
Reserved: 2024-09-02T16:00:02.423Z
Link: CVE-2024-45600
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-12-26T22:15:13.583
Modified: 2024-12-26T22:15:13.583
Link: CVE-2024-45600
Redhat
No data.