CVE-2022-39323

CVE-2022-39323

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been patched, please upgrade to version 10.0.4. As a workaround, disable login with user_token on API Rest.

Source: CVE-2022-39323

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다