CVE-2023-41320: high-severity vulnerability in glpi-project glpi
Account takeover via SQL Injection in UI layout preferences in GLPI
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
GLPI has a SQL injection flaw in its UI layout preferences feature that allows attackers to take over administrator accounts. An attacker can exploit this vulnerability to gain full control of the system.
A SQL injection vulnerability exists in GLPI's UI layout preferences management functionality, allowing unauthenticated or low-privileged attackers to inject malicious SQL queries. This injection can be leveraged to extract and modify sensitive data, including administrator credentials, leading to account takeover and complete system compromise.
In the same product, most dangerous first.