CVE-2022-39323: high-severity vulnerability in glpi-project glpi
SQL Injection on REST API in GLPI
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
GLPI's REST API has a SQL injection vulnerability in the user_token parameter that allows attackers to extract sensitive data through time-based attacks. This flaw lets unauthorized users bypass authentication and access or manipulate the system's database.
A time-based SQL injection vulnerability exists in the GLPI REST API's user_token authentication mechanism (CWE-89), allowing remote attackers to execute arbitrary SQL queries without authentication. The attack exploits insufficient input validation in the API endpoint, enabling data exfiltration through timing side-channels; patched in version 10.0.4.
In the same product, most dangerous first.