Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.
References
Configurations
History
07 Feb 2025, 15:24
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CPE | cpe:2.3:a:infotel:tasklists:*:*:*:*:*:glpi:*:* | |
First Time |
Infotel
Infotel tasklists |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | () https://github.com/InfotelGLPI/tasklists/commit/6444026e3d2b8fb22d5e5ab03fb86056e1ac9e43 - Patch | |
References | () https://github.com/InfotelGLPI/tasklists/security/advisories/GHSA-c6fw-xw9x-gwjw - Vendor Advisory |
30 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-30 19:15
Updated : 2025-02-07 15:24
NVD link : CVE-2024-56801
Mitre link : CVE-2024-56801
CVE.ORG link : CVE-2024-56801
JSON object : View
Products Affected
infotel
- tasklists
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')