Impact
GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack.
By default, GLPI inventory endpoint requires no authentication.
Patches
Upgrade to 10.0.7
Workarounds
Disable native inventory.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].
Impact
GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack.
By default, GLPI inventory endpoint requires no authentication.
Patches
Upgrade to 10.0.7
Workarounds
Disable native inventory.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].