Skip to content

Known CVE

GLPI 10.0.10-10.0.14 - SQL Injection

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it.

CVE-2024-29889

High2024CVSS 7.1CWE-89

cve2024 · glpi · sqli · authenticated · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website