Skip to content

SQL injection on search pages

Low
trasher published GHSA-5w33-4wrx-8hvw Jun 9, 2022

Package

GLPI (GLPI)

Affected versions

10.0.0

Patched versions

10.0.1

Description

It is possible to add extra information by SQL injection on search pages.

User must be logged in, and it seems injection real capacities has low impact.

Severity

Low

CVE ID

CVE-2022-29250

Weaknesses

No CWEs