SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-40638

An authenticated user can exploit multiple SQL injection vulnerabilities.

HIGH 8.8EPSS 37.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 37.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
37.15% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
glpi-project/glpi
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.