Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28849


GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.7 contains a patch for this issue. As a workaround, disable native inventory.


Published

2023-04-05T18:15:08.447

Last Modified

2024-11-21T07:56:09.193

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-79
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application glpi-project glpi < 10.0.7 Yes

References