ZeroHour

CVE-2024-40638

large1

Authenticated SQL Injection in GLPI Enables Account Takeover

CVSS 3.1
8.8 high
EPSS
37%p98
Published
()
Modified
AI analysis

Multiple SQL injection vulnerabilities (CWE-89) exist in GLPI, a free and open-source IT asset management platform. The flaws are triggered by an authenticated user with low privileges sending crafted input to the affected application, requiring no user interaction. Successful exploitation allows read and modification of database content, and one of the injections can be used to alter another user's account data and take control of that account, potentially yielding higher-privileged access. Any organization running GLPI prior to version 10.0.17 is affected. No exploitation has been confirmed yet (no public PoC, not in CISA KEV), but the elevated EPSS score of 37.2% (98th percentile) indicates a significant likelihood of exploitation within the next 30 days.

What to do: Upgrade GLPI to version 10.0.17 immediately, as this release fixes all reported SQL injection issues. If immediate upgrade is not possible, review user accounts for unauthorized modifications, monitor logs for suspicious database queries or account changes, and restrict privileges of low-privileged users who can reach the affected functionality.

Affected
glpi-project GLPIversions prior to 10.0.17
Estimated exposure
largetens of thousands of internet-facing GLPI instances, likely 100,000+ total deployments worldwide (est.) — GLPI is a widely adopted self-hosted open-source ITSM suite; public internet scans index tens of thousands of instances, with many more installed on internal networks, so this is an estimate rather than an exact count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.

Vendors
glpi-project
Products
glpi
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.