GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 28 Jan 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Glpi-project
Glpi-project glpi |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:17:58.452Z
Reserved: 2024-03-21T15:12:08.997Z
Link: CVE-2024-29889
Updated: 2024-08-02T01:17:58.452Z
Status : Analyzed
Published: 2024-05-07T14:15:10.330
Modified: 2025-01-28T03:40:57.580
Link: CVE-2024-29889
No data.
OpenCVE Enrichment
No data.
Weaknesses