CVE-2023-36808: high-severity vulnerability in glpi-project glpi
GLPI vulnerable to SQL injection through Computer Virtual Machine information
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
GLPI, a free IT management software, has a flaw in its Computer Virtual Machine form that allows attackers to inject malicious SQL commands. This could let an attacker steal, modify, or delete sensitive data from the system.
SQL injection vulnerability exists in the Computer Virtual Machine form processing in GLPI versions 0.80 through 10.0.7, exploitable via inventory requests without proper input sanitization. An attacker with access to submit VM information can execute arbitrary SQL queries, potentially compromising data integrity and confidentiality of the entire database.
In the same product, most dangerous first.