HTTP: GLPI-Project GLPI Inventory Agent SQL Injection

This signature detects attempts to exploit a known vulnerability against GLPI-Project. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.

Affected Products

Glpi-project glpi

Short Name
HTTP:SQL:INJ:GLPI-PROJECT-INVEN
Severity
Critical
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Agent CVE-2023-35924 CVE-2023-46727 GLPI GLPI-Project Injection Inventory SQL
Release Date
09/22/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3693
False Positive
Rarely
Vendors

Glpi-project

Found a potential security threat?