Vulnerabilità
CVE-2026-49469
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 03:55
Descrizione
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26.
Alias e classificazioni
CWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
Dettagli tecnici minimizzati
Nessun dato grezzo- cisa kev
- False
Provenienza
Riferimenti pubblici
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/releases/tag/11.0.8 - https://github.com/glpi-project/glpi/security/advisories/GHSA-3cgm-rj32-hfwf
https://github.com/glpi-project/glpi/security/advisories/GHSA-3cgm-rj32-hfwf - https://github.com/glpi-project/glpi/releases/tag/10.0.26
https://github.com/glpi-project/glpi/releases/tag/10.0.26 - https://github.com/glpi-project/glpi/commit/d413b48ea97b2f73ba30c90ae0d029aac860f71a
https://github.com/glpi-project/glpi/commit/d413b48ea97b2f73ba30c90ae0d029aac860f71a - https://github.com/glpi-project/glpi/commit/4fb3056bcd292b515acce96887f1376ce6d5aba8
https://github.com/glpi-project/glpi/commit/4fb3056bcd292b515acce96887f1376ce6d5aba8
Correlazione EudorIA
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.