CVE-2023-41320
Last modified
CVE-2023-41320 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. EPSS estimates a 32.10% chance of exploitation in the next 30 days.
Description
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This injection can be use to takeover an administrator account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | >= 10.0.0, < 10.0.10 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-41320?
How severe is CVE-2023-41320?
How do I fix CVE-2023-41320?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-41314The api /api/snapshot and /api/get_log_file would allow unau…8.2
- CVE-2023-41316Tolgee is an open-source localization platform. Due to lack …5.4
- CVE-2023-41317The Apollo Router is a configurable, high-performance graph …5.9
- CVE-2023-41318matrix-media-repo is a highly customizable multi-domain medi…5.4
- CVE-2023-41319Fides is an open-source privacy engineering platform for man…7.2
- CVE-2023-4132A use-after-free vulnerability was found in the siano smsusb…5.5
- CVE-2023-41321GLPI stands for Gestionnaire Libre de Parc Informatique is a…6.5
- CVE-2023-41322GLPI stands for Gestionnaire Libre de Parc Informatique is a…8.8
- CVE-2023-41323GLPI stands for Gestionnaire Libre de Parc Informatique is a…5.3
- CVE-2023-41324GLPI stands for Gestionnaire Libre de Parc Informatique is a…8.8
- CVE-2023-41325OP-TEE is a Trusted Execution Environment (TEE) designed as …6.7
- CVE-2023-41326GLPI stands for Gestionnaire Libre de Parc Informatique is a…8.8
Are you affected by CVE-2023-41320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
