Skip to content

SQL injection through plugin controller

Moderate
trasher published GHSA-92q5-pfr8-r9r2 Sep 14, 2022

Package

glpi (glpi)

Affected versions

>= 0.72

Patched versions

10.0.3

Description

Impact

Request input is not properly validated in plugin controller and can be used to access low-level API of Plugin class. Attacker can, for instance, alter database data.
Attacker must have "General setup" update rights to be able to perform this attack.

Patches

Upgrade to 10.0.3.

Workarounds

Remove front/plugin.form.php script.

References

.

Severity

Moderate
5.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N

CVE ID

CVE-2022-35946

Weaknesses

Credits