packetstormsecurity.com
http://packetstormsecurity.com/files/171656/GLPI-10.0.2-SQL-Injection-Remote-Code-Execution.html CVE-2022-31056
CRITICAL
SQL injection with _actor parameter in GLPI
Record summary
CVE-2022-31056 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 10.0.0, < 10.0.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBGLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration)ExploitDB exploitby Nuri ÇilengirNot analyzed1 file
References
2github.com
https://github.com/glpi-project/glpi/security/advisories/GHSA-9q9x-7xxh-w4cg