CVE-2022-29250SQL Injection in Glpi

CWE-89SQL Injection2 documents2 sources
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 51.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 9

Description

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulnerability a user must be logged in.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5glpi-project/glpi< 10.0.1
NVDglpi-project/glpi10.0.0

🔴Vulnerability Details

1
OSV
CVE-2022-29250: GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing2022-06-09