GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/glpi-project/glpi/security/advisories/GHSA-8843-r3m7-gfqx | Vendor Advisory | 
Configurations
                    History
                    20 Nov 2024, 15:30
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 8.8 | 
| First Time | Glpi-project Glpi-project glpi | |
| References | () https://github.com/glpi-project/glpi/security/advisories/GHSA-8843-r3m7-gfqx - Vendor Advisory | 
18 Nov 2024, 17:11
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
15 Nov 2024, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-11-15 18:15
Updated : 2024-11-20 15:30
NVD link : CVE-2024-40638
Mitre link : CVE-2024-40638
CVE.ORG link : CVE-2024-40638
JSON object : View
Products Affected
                glpi-project
- glpi
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
