Beveiligingsadvies

CVE-2023-36808

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-07-05 20:52:48
Laatst bijgewerkt 2024-10-18 19:39:38
Toegewezen door GitHub_M
CVSS-score 8.6
Status PUBLISHED

Beschrijving

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.