CVE-2019-10232

high-risk
Published 2019-03-27

Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

Do I need to act?

!
88.7% chance of exploitation in next 30 days
EPSS score — higher than 11% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 684d4fc423652ec7dde21cac4d41c2df53f56b3c
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Vendors

57
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 20/34 · Moderate
Exposure 5/34 · Minimal