CVE-2024-29889: high-severity vulnerability in glpi-project glpi
GLPI contains an SQL injection through the saved searches
Published · Updated
Patch soon. It has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
GLPI has a security flaw in its saved searches feature that allows logged-in users to inject malicious SQL commands. An attacker could use this to alter another user's account data and take control of it.
SQL injection vulnerability in the saved searches functionality of GLPI prior to version 10.0.15 allows authenticated attackers to execute arbitrary SQL queries. The attack vector requires valid user credentials and can result in unauthorized modification of user account data and privilege escalation through account takeover.
In the same product, most dangerous first.