VYPR
Unrated severityNVD Advisory· Published May 5, 2020· Updated Aug 4, 2024

SQL injection on addme_observer and addme_assign in GLPI

CVE-2020-11032

Description

In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.