Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31082

Опубликовано: 27 июн. 2022
Источник: nvd
CVSS3: 5.8
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection can be made using package deployment tasks. This issue has been resolved in version 1.0.2. Users are advised to upgrade. Users unable to upgrade should delete the front/deploypackage.public.php file if they are not using the deploy tasks feature.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:glpi-project:glpi_inventory:*:*:*:*:*:*:*:*
Версия до 1.0.2 (исключая)

EPSS

Процентиль: 51%
0.00282
Низкий

5.8 Medium

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 5.8
ubuntu
больше 3 лет назад

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection can be made using package deployment tasks. This issue has been resolved in version 1.0.2. Users are advised to upgrade. Users unable to upgrade should delete the `front/deploypackage.public.php` file if they are not using the `deploy tasks` feature.

CVSS3: 5.8
debian
больше 3 лет назад

GLPI is a Free Asset and IT Management Software package, Data center m ...

EPSS

Процентиль: 51%
0.00282
Низкий

5.8 Medium

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89
CWE-89