GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-05-07T14:05:31.713Z
Updated: 2024-06-06T16:08:34.715Z
Reserved: 2024-03-21T15:12:08.997Z
Link: CVE-2024-29889
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-05-07T14:15:10.330
Modified: 2024-05-07T20:07:58.737
Link: CVE-2024-29889
JSON object: View
Redhat Information
No data.
CWE