NA

CVE-2023-41320

Published: 27/09/2023 Updated: 29/09/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This injection can be use to takeover an administrator account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project glpi

Github Repositories

POC for cve 2023 41320 GLPI

CVE_2023_41320 POC for CVE 2023 41320 on GLPI Vulnerability Condition Score CVSS Vulnerable versions SQL Injection Authenticated User 81 1000 ≤ Version ≤ 1009 Impact: SQL Injection in an update clause (be careful, do not forget the "WHERE" thanks Issam for the test 😄) Account Takeover (or privesc on the webapp) Remote Code Execution (in some