CVE-2022-29250
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
09/06/2022
Last modified:
16/06/2022
Description
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulnerability a user must be logged in.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:glpi-project:glpi:10.0.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:glpi-project:glpi:10.0.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:glpi-project:glpi:10.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:glpi-project:glpi:10.0.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:glpi-project:glpi:10.0.0:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



