CVE-2024-29889highCWE-89

CVE-2024-29889: high-severity vulnerability in glpi-project glpi

GLPI contains an SQL injection through the saved searches

Published · Updated

48Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.1epss 63%
exploitation probability
63%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
In short

GLPI has a security flaw in its saved searches feature that allows logged-in users to inject malicious SQL commands. An attacker could use this to alter another user's account data and take control of it.

Technical detail

SQL injection vulnerability in the saved searches functionality of GLPI prior to version 10.0.15 allows authenticated attackers to execute arbitrary SQL queries. The attack vector requires valid user credentials and can result in unauthorized modification of user account data and privilege escalation through account takeover.

Summary generated and translated by AI from the official description.
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
glpi-project · glpi