GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 0.78
A SQL injection vulnerability has been identified in GLPI, a free asset and IT management software, affecting versions 0.78 and later. This vulnerability allows an administrator user to perform SQL injection through the rules configuration forms.
Exploitation of this vulnerability allows for SQL injection, which could lead to unauthorized data access or manipulation in the database.
Users are advised to upgrade to GLPI version 10.0.18.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.