CVE-2022-29250
Summary
| CVE | CVE-2022-29250 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-09 20:15:00 UTC |
| Updated | 2022-06-16 19:35:00 UTC |
| Description | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulnerability a user must be logged in. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Glpi-project | Glpi | 10.0.0 | - | All | All |
| Application | Glpi-project | Glpi | 10.0.0 | beta | All | All |
| Application | Glpi-project | Glpi | 10.0.0 | rc1 | All | All |
| Application | Glpi-project | Glpi | 10.0.0 | rc2 | All | All |
| Application | Glpi-project | Glpi | 10.0.0 | rc3 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SQL injection on search pages · Advisory · glpi-project/glpi · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.