Vulnerability record · CVE-2022-31061 · published 28 June 2022
CVE-2022-31061: GLPI unauthenticated SQL injection on login page
Glpi Project · Glpi
GLPI contains a SQL injection flaw reachable from the login page. Because no credentials are needed, any network attacker can attempt to inject SQL before authenticating. The vendor states there are no known workarounds, so upgrading is the only fix.
Description
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8 and high EPSS makes this an urgent patch target despite no KEV listing.
What it is
GLPI contains a SQL injection flaw reachable from the login page. Because no credentials are needed, any network attacker can attempt to inject SQL before authenticating. The vendor states there are no known workarounds, so upgrading is the only fix.
Impact
An attacker can read and modify database contents and potentially disrupt the application, given the high confidentiality, integrity and availability impact in the CVSS vector. Full compromise of the GLPI database is the realistic worst case.
Attack surface
Reachable over the network via the login page with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or intranet-exposed GLPI instance is in scope.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation attempts. References are patch and advisory links only, with no public exploit tag.
What to do
- Upgrade GLPI to a version containing the fix in commit 21ae07d00d0b3230f6235386e98388cfc5bb0514 as soon as possible.
- If immediate upgrade is impossible, restrict network access to the GLPI login page to trusted networks or place it behind an authenticating reverse proxy.
- Review database logs and application logs for anomalous SQL or error patterns originating from the login endpoint.
- Rotate database credentials and any secrets stored in GLPI after patching, in case of prior compromise.
- Monitor the vendor advisory GHSA-w2gc-v2gm-q7wq for updated guidance, since no workaround exists.
Detection
- Inspect web server and WAF logs for SQL metacharacters or injection patterns in requests to the GLPI login endpoint.
- Alert on database errors or unusual query volume correlated with login page requests.
- Baseline normal login page request parameters and flag deviations, especially unexpected SQL keywords.
- Review GLPI application logs for authentication or database exceptions occurring without a preceding successful login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/glpi-project/glpi/commit/21ae07d00d0b3230f6235386e98388cfc5bb0514 | PatchThird Party Advisory |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-w2gc-v2gm-q7wq | Third Party Advisory |
| https://github.com/glpi-project/glpi/commit/21ae07d00d0b3230f6235386e98388cfc5bb0514 | PatchThird Party Advisory |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-w2gc-v2gm-q7wq | Third Party Advisory |
Track CVE-2022-31061 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-31061), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.