GLPI Inventory Plugin
cpe:2.3:a:glpi-project:glpi_inventory:*:*:*:*:*:*:*
- <= 1.6.5
A SQL injection vulnerability has been identified in the GLPI Inventory Plugin, specifically in versions through 1.6.5. The issue arises from the handling of non-sanitized user input in reports, which can be exploited by users with the appropriate rights. This vulnerability has been addressed in version 1.6.6.
Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries and potentially access or modify sensitive data.
Users can upgrade to GLPI Inventory Plugin version 1.6.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.