High severity7.1NVD Advisory· Published Jul 17, 2020· Updated Jun 17, 2026
CVE-2020-15108
CVE-2020-15108
Description
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
Affected products
3cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: <9.5.1
- (no CPE)range: <9.5.1
- (no CPE)range: < 9.5.1
Patches
Vulnerability mechanics
References
3- github.com/glpi-project/glpi/commit/a4baa64114eb92fd2adf6056a36e0582324414banvdPatchThird Party Advisory
- github.com/glpi-project/glpi/pull/6684nvdThird Party Advisory
- github.com/glpi-project/glpi/security/advisories/GHSA-qv6w-68gq-wx2vnvdThird Party Advisory
News mentions
0No linked articles in our index yet.