CVE-2017-11475 — SQL Injection in Glpi
Severity
8.8HIGHNVD
EPSS
0.2%
top 59.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 20
Latest updateMay 17
Description
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages1 packages
Patches
🔴Vulnerability Details
2💬Community
3Bugzilla▶
CVE-2017-11474 CVE-2017-11475 glpi: SQL injection in ajax/common.tabs.php and front/rulesengine.test.php↗2017-07-20
Bugzilla▶
CVE-2017-11474 CVE-2017-11475 glpi: SQL injection in ajax/common.tabs.php and front/rulesengine.test.php [fedora-all]↗2017-07-20
Bugzilla▶
CVE-2017-11474 CVE-2017-11475 glpi: SQL injection in ajax/common.tabs.php and front/rulesengine.test.php [epel-7]↗2017-07-20