Skip to content

Unauthenticated SQL queries can lead to Information Disclosure

Critical
cedric-anne published GHSA-3v9g-47fc-4f8q Sep 15, 2021

Package

plugin uninstall for glpi (glpi)

Affected versions

< 2.7.1

Patched versions

2.7.1

Description

Impact

Every instance using uninstall plugin for GLPI

Patches

patched in 2.7.1 version

Workarounds

Remove the plugin from glpi (directly from the FS)

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2021-40863

Weaknesses

No CWEs

Credits