CVE-2023-37278

MEDIUM

GLPI < 10.0.9 - Authenticated SQL Injection via Dashboards Administration

Title source: llm
STIX 2.1

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An administrator can trigger SQL injection via dashboards administration. This vulnerability has been patched in version 10.0.9.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://github.com/glpi-project/glpi/releases/tag/10.0.9

Scores

CVSS v3 6.8
EPSS 0.0031
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
glpi-project/glpi < 10.0.9
Published Jul 13, 2023
Tracked Since Feb 18, 2026