CVE-2023-28849

CRITICAL

GLPI 10.0.0-10.0.7 - Unauthenticated SQL Injection and Stored Cross-Site Scripting via Inventory Endpoint

Title source: llm
STIX 2.1

Description

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.7 contains a patch for this issue. As a workaround, disable native inventory.

References (2)

Core 2
Core References
Patch, Release Notes x_refsource_misc
https://github.com/glpi-project/glpi/releases/tag/10.0.7

Scores

CVSS v3 10.0
EPSS 0.0107
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-79 CWE-89
Status published
Products (1)
glpi-project/glpi 10.0.0 - 10.0.7
Published Apr 05, 2023
Tracked Since Feb 18, 2026