Vulnerability record · CVE-2023-36808 · published 5 July 2023
CVE-2023-36808: GLPI SQL injection in Computer Virtual Machine form and inventory request
Glpi Project · Glpi
GLPI versions from 0.80 up to but not including 10.0.8 contain a SQL injection flaw reachable through the Computer Virtual Machine form and the GLPI inventory request. The vendor advisory and release notes confirm version 10.0.8 patches the issue. Because the injection point is network-reachable and requires no authentication or user interaction, it is a serious pre-auth database compromise risk.
Description
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and no user interaction, plus a very high EPSS percentile, makes this a top remediation priority despite no KEV listing.
What it is
GLPI versions from 0.80 up to but not including 10.0.8 contain a SQL injection flaw reachable through the Computer Virtual Machine form and the GLPI inventory request. The vendor advisory and release notes confirm version 10.0.8 patches the issue. Because the injection point is network-reachable and requires no authentication or user interaction, it is a serious pre-auth database compromise risk.
Impact
An unauthenticated attacker can inject arbitrary SQL, potentially reading, modifying, or deleting data in the GLPI database and, depending on database privileges, executing database-level functions. This can expose asset, inventory, and user data managed by GLPI.
Attack surface
Reached over the network via the Computer Virtual Machine form and the GLPI inventory request endpoint. The CVSS vector shows no privileges required and no user interaction, so the injection is exploitable pre-authentication.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is 0.478 (98.8th percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Upgrade GLPI to version 10.0.8 or later, which contains the vendor patch.
- If immediate upgrade is not possible, disable native inventory as the vendor workaround states.
- Restrict network access to the GLPI inventory and Computer Virtual Machine endpoints to trusted management networks.
- Review database account privileges used by GLPI and remove unnecessary DDL or file-level permissions.
- Monitor vendor advisory GHSA-vf5h-jh9q-2gjm for any updated guidance.
Detection
- Inspect web and application logs for SQL metacharacters or unusual payloads in requests to the Computer Virtual Machine form and inventory endpoints.
- Enable and review database query logging for anomalous SQL originating from the GLPI application account.
- Alert on unexpected changes to GLPI database contents or schema that do not correlate with normal administrative activity.
- Correlate inventory endpoint access from untrusted source IPs with subsequent database errors or unusual query patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/glpi-project/glpi/releases/tag/10.0.8 | Release Notes |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-vf5h-jh9q-2gjm | Vendor Advisory |
| https://github.com/glpi-project/glpi/releases/tag/10.0.8 | Release Notes |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-vf5h-jh9q-2gjm | Vendor Advisory |
Track CVE-2023-36808 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36808), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.