GLPI allows unauthenticated SQL injection through the inventory endpoint
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.5epss 86%
from disclosure to weapon16 days
Published on NVDMar 18
1st PoC+16d
metasploitMar 12
VulnCheck+30d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
glpi-project · glpipublic PoCs found — 4
vulncheckvulncheck.com/xdb/dea8a438cfb1unverifiedvulncheckvulncheck.com/xdb/53fa210113abunverifiedvulncheckvulncheck.com/xdb/31c0489944d6unverifiedvulncheckvulncheck.com/xdb/739c6a88cbebunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.