Unrated severityNVD Advisory· Published Oct 7, 2020· Updated Aug 4, 2024
SQL injection in GLPI
CVE-2020-15176
Description
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker is able to exfiltrate sensitive information like passwords, reset tokens, personal details, and more. The issue is patched in version 9.5.2
Affected products
1- Range: >= 0.6.8, < 9.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/glpi-project/glpi/commit/f021f1f365b4acea5066d3e57c6d22658cf32575mitrex_refsource_CONFIRM
- github.com/glpi-project/glpi/security/advisories/GHSA-x93w-64x9-58qwmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.