Unrated severityNVD Advisory· Published May 5, 2020· Updated Aug 4, 2024
SQL injection on addme_observer and addme_assign in GLPI
CVE-2020-11032
Description
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.
Affected products
1- Range: < 9.4.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/glpi-project/glpi/security/advisories/GHSA-344w-34h9-wwhhmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.