CVE-2017-11475SQL Injection in Glpi

CWE-89SQL Injection6 documents4 sources
Severity
8.8HIGHNVD
EPSS
0.2%
top 59.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 20
Latest updateMay 17

Description

GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDglpi-project/glpi9.1.5.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3f8q-6q6f-h89r: GLPI before 92022-05-17
OSV
CVE-2017-11475: GLPI before 92017-07-20

💬Community

3
Bugzilla
CVE-2017-11474 CVE-2017-11475 glpi: SQL injection in ajax/common.tabs.php and front/rulesengine.test.php2017-07-20
Bugzilla
CVE-2017-11474 CVE-2017-11475 glpi: SQL injection in ajax/common.tabs.php and front/rulesengine.test.php [fedora-all]2017-07-20
Bugzilla
CVE-2017-11474 CVE-2017-11475 glpi: SQL injection in ajax/common.tabs.php and front/rulesengine.test.php [epel-7]2017-07-20