Vulnerability CVE-2024-31456: Information

Description

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. This vulnerability is fixed in 10.0.15.

Published: May 7, 2024
Modified: May 7, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.15-alt110.0.15-alt1ALT-PU-2024-7181-1345902Fixed
glpisisyphus_e2k10.0.15-alt110.0.15-alt1ALT-PU-2024-7250-1-Fixed
glpisisyphus_loongarch6410.0.15-alt110.0.15-alt1ALT-PU-2024-7236-1-Fixed
glpip1010.0.15-alt110.0.15-alt1ALT-PU-2024-7305-2347218Fixed
glpip10_e2k10.0.15-alt110.0.15-alt1ALT-PU-2024-7453-1-Fixed

References to Advisories, Solutions, and Tools