HTTP: GLPI-Project GLPI Auth.php SQL Injection

This signature detects attempts to exploit a known vulnerability against GLPI. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

Affected Products

Glpi-project glpi

References

CVE: CVE-2022-39323

Short Name
HTTP:SQL:INJ:GLPI-AUTH-PHP-SQLI
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Auth.php CVE-2022-31061 CVE-2022-39323 GLPI GLPI-Project Injection SQL
Release Date
07/21/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Glpi-project

CVSS Score

7.5

Found a potential security threat?