In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
2020-07-17T21:15:12.780
2024-11-21T05:04:49.693
Modified
CVSSv3.1: 7.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | glpi-project | glpi | < 9.5.1 | Yes |