PT-2020-4300 · Teclib+1 · Glpi+1

·

CVE-2020-15176

·

Published

2020-10-07

·

Updated

2024-05-22

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: GLPI versions prior to 9.5.2
Description: The issue is related to the incorrect neutralization of special elements used in SQL commands, which can allow a remote attacker to execute arbitrary SQL queries to the database in the target system by sending a specially crafted request to the vulnerable application. This can lead to the exfiltration of sensitive information, including passwords, reset tokens, and personal details.
Recommendations: For versions prior to 9.5.2, update to version 9.5.2 or later to resolve the issue. As a temporary workaround, consider restricting input that gets put into SQL queries to prevent SQL Injection. Avoid using back ticks in input that gets put into SQL queries until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3130
ALT-PU-2020-3162
ALT-PU-2024-8094
BDU:2020-04793
CVE-2020-15176
GHSA-X93W-64X9-58QW

Affected Products

Alt Linux
Glpi