Vulnerability Details CVE-2023-35924
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.132
EPSS Ranking 93.8%
CVSS Severity
CVSS v3 Score 8.6
Products affected by CVE-2023-35924
-
cpe:2.3:a:glpi-project:glpi:10.0.0
-
cpe:2.3:a:glpi-project:glpi:10.0.1
-
cpe:2.3:a:glpi-project:glpi:10.0.2
-
cpe:2.3:a:glpi-project:glpi:10.0.3
-
cpe:2.3:a:glpi-project:glpi:10.0.4
-
cpe:2.3:a:glpi-project:glpi:10.0.5
-
cpe:2.3:a:glpi-project:glpi:10.0.6
-
cpe:2.3:a:glpi-project:glpi:10.0.7