CVE-2024-40638
large1Authenticated SQL Injection in GLPI Enables Account Takeover
Multiple SQL injection vulnerabilities (CWE-89) exist in GLPI, a free and open-source IT asset management platform. The flaws are triggered by an authenticated user with low privileges sending crafted input to the affected application, requiring no user interaction. Successful exploitation allows read and modification of database content, and one of the injections can be used to alter another user's account data and take control of that account, potentially yielding higher-privileged access. Any organization running GLPI prior to version 10.0.17 is affected. No exploitation has been confirmed yet (no public PoC, not in CISA KEV), but the elevated EPSS score of 37.2% (98th percentile) indicates a significant likelihood of exploitation within the next 30 days.
What to do: Upgrade GLPI to version 10.0.17 immediately, as this release fixes all reported SQL injection issues. If immediate upgrade is not possible, review user accounts for unauthorized modifications, monitor logs for suspicious database queries or account changes, and restrict privileges of low-privileged users who can reach the affected functionality.
| glpi-project GLPI | versions prior to 10.0.17 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.
- Vendors
- glpi-project
- Products
- glpi
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.