All errata/t7/ALT-PU-2013-1123-1
ALT-PU-2013-1123-1

Package update glpi in branch t7

Version0.84.3-alt1
Published2013-11-17
Max severityHIGH
Severity:

Closed issues (4)

CVE-2013-2226
HIGH7.5

Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.

Published: 2014-05-14Modified: 2025-04-12
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P

Closed bugs (1)

Обновить до версии 0.83.91