CVE-2024-45600 Information
Dec 27, 2024
cve
Description
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13 an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.
Reference
https://github.com/pluginsGLPI/fields/commit/eb927b0f084ee4ef6c87ab2eb7a15e99369e74ae#diff-a7024a397fba9a026157683da73cc675ec6b73bd900374b3836bcdc76ec7bd5cR1166 https://github.com/pluginsGLPI/fields/security/advisories/GHSA-wwxw-64g6-2992
Share on: