Vulnerability Description
An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teclib-Edition | Fields | <= 1.9.2 |
Related Weaknesses (CWE)
References
- https://github.com/pluginsGLPI/fields/blob/master/ajax/reorder.phpThird Party Advisory
- https://github.com/pluginsGLPI/fields/pull/317Third Party Advisory
- https://github.com/pluginsGLPI/fields/releases/tag/1.10.0Release NotesThird Party Advisory
- https://github.com/pluginsGLPI/fields/blob/master/ajax/reorder.phpThird Party Advisory
- https://github.com/pluginsGLPI/fields/pull/317Third Party Advisory
- https://github.com/pluginsGLPI/fields/releases/tag/1.10.0Release NotesThird Party Advisory
FAQ
What is CVE-2019-12723?
CVE-2019-12723 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.
How severe is CVE-2019-12723?
CVE-2019-12723 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12723?
Check the references section above for vendor advisories and patch information. Affected products include: Teclib-Edition Fields.