Untriaged
Permalink
CVE-2026-26263
8.1 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
GLPI has an Unauthenticated SQL Injection via Search engine
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.
References
-
https://github.com/glpi-project/glpi/security/advisories/GHSA-346p-qj3v-9rxj x_refsource_CONFIRM
Affected products
glpi
- ==>= 11.0.0, < 11.0.6
Package maintainers
-
@liberodark liberodark <liberodark@gmail.com>