← Back to CVE List

CVE-2022-21720

Published: 2022-01-28T11:15Z
Last Modified: 2024-11-21T06:45Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt