← Vulnerability feed

Vulnerability record · CVE-2023-36808 · published 5 July 2023

CVE-2023-36808: GLPI SQL injection in Computer Virtual Machine form and inventory request

Glpi Project · Glpi

GLPI versions from 0.80 up to but not including 10.0.8 contain a SQL injection flaw reachable through the Computer Virtual Machine form and the GLPI inventory request. The vendor advisory and release notes confirm version 10.0.8 patches the issue. Because the injection point is network-reachable and requires no authentication or user interaction, it is a serious pre-auth database compromise risk.

9.8 CVSS 3.1 Critical EPSS 48% · top 1.2% CWE-89 · SQL injection
9.8CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and no user interaction, plus a very high EPSS percentile, makes this a top remediation priority despite no KEV listing.

What it is

GLPI versions from 0.80 up to but not including 10.0.8 contain a SQL injection flaw reachable through the Computer Virtual Machine form and the GLPI inventory request. The vendor advisory and release notes confirm version 10.0.8 patches the issue. Because the injection point is network-reachable and requires no authentication or user interaction, it is a serious pre-auth database compromise risk.

Impact

An unauthenticated attacker can inject arbitrary SQL, potentially reading, modifying, or deleting data in the GLPI database and, depending on database privileges, executing database-level functions. This can expose asset, inventory, and user data managed by GLPI.

Attack surface

Reached over the network via the Computer Virtual Machine form and the GLPI inventory request endpoint. The CVSS vector shows no privileges required and no user interaction, so the injection is exploitable pre-authentication.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is 0.478 (98.8th percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Upgrade GLPI to version 10.0.8 or later, which contains the vendor patch.
  • If immediate upgrade is not possible, disable native inventory as the vendor workaround states.
  • Restrict network access to the GLPI inventory and Computer Virtual Machine endpoints to trusted management networks.
  • Review database account privileges used by GLPI and remove unnecessary DDL or file-level permissions.
  • Monitor vendor advisory GHSA-vf5h-jh9q-2gjm for any updated guidance.

Detection

  • Inspect web and application logs for SQL metacharacters or unusual payloads in requests to the Computer Virtual Machine form and inventory endpoints.
  • Enable and review database query logging for anomalous SQL originating from the GLPI application account.
  • Alert on unexpected changes to GLPI database contents or schema that do not correlate with normal administrative activity.
  • Correlate inventory endpoint access from untrusted source IPs with subsequent database errors or unusual query patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-36808 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2025-24799GLPI unauthenticated SQL injection in inventory endpointGLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issu…EPSS 87%analysed9.8CVE-2023-46727GLPI inventory endpoint SQL injectionGLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authent…EPSS 68%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 0.85%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2023-36808), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.