CVE-2022-21720

GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.
Configurations

Configuration 1

cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

Information

Published : 2022-01-28 11:15

Updated : 2022-02-02 05:50


NVD link : CVE-2022-21720

Mitre link : CVE-2022-21720

Products Affected
No products.
CWE