Vulnerability CVE-2023-28838: Information

Description

GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell on the server. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, remove `Assistance > Statistics` and `Tools > Reports` read rights from every user.

Severity: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Published: April 5, 2023
Modified: April 12, 2023
Error type identifier: CWE-89

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.7-alt110.0.14-alt1ALT-PU-2023-1801-1320515Fixed
glpisisyphus_e2k10.0.7-alt110.0.14-alt1ALT-PU-2023-3527-1-Fixed
glpip109.5.13-alt110.0.14-alt1ALT-PU-2023-1932-1322040Fixed
glpip10_e2k9.5.13-alt110.0.14-alt1ALT-PU-2023-3790-1-Fixed
glpip99.5.13-alt19.5.13-alt1ALT-PU-2023-2081-1323561Fixed
glpip9_e2k9.5.13-alt19.5.13-alt1ALT-PU-2023-5377-1-Fixed
glpip9_mipsel9.5.13-alt19.5.13-alt1ALT-PU-2023-6334-1-Fixed
glpic10f19.5.13-alt19.5.13-alt1ALT-PU-2023-5122-3327798Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      Start including
      10.0.0
      End excliding
      10.0.7

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      Start including
      0.50
      End excliding
      9.5.13