CVE-2013-2226

high
Published 2014-05-14 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.glpi-project.org/spip.php?page=annonce&id_breve=297&lang=en&debut_autres_breves=

Application impact

VendorProductVersionsFixed
glpi-projectglpi{"endIncluding":"0.83.8"}
glpi-projectglpi0.83
glpi-projectglpi0.83.1
glpi-projectglpi0.83.2
glpi-projectglpi0.83.3
glpi-projectglpi0.83.4
glpi-projectglpi0.83.5
glpi-projectglpi0.83.6
glpi-projectglpi0.83.7
glpi-projectglpi0.83.31

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.