CVE-2024-31456SQL Injection in Glpi

CWE-89SQL Injection3 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
24.0%
top 3.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7
Latest updateJan 28

Description

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. This vulnerability is fixed in 10.0.15.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5glpi-project/glpi< 10.0.15
NVDglpi-project/glpi9.3.010.0.15

Patches

🔴Vulnerability Details

1
OSV
CVE-2024-31456: GLPI is a Free Asset and IT Management Software package2024-05-07

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS GLPI Authenticated SQL Injection in Map Search (CVE-2024-31456)2026-01-28