Exploiting GLPI during a Red Team engagement
blog.quarkslab.com | vulnerability | #php | #sql-injection | #red-team | #ssrf | #glpi | #cve-2024-27096
Summary
During a Red Team engagement, Quarkslab developed a 1-day for GLPI CVE-2023-43813, then found an arbitrary object instantiation leading to SSRF (CVE-2024-27098) and a SQL injection (CVE-2024-27096).
- Published
- Collected
Skip to content