CVE-2026-22044
EUVD-2026-537504.02.2026, 18:16
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| glpi-project | glpi | 0.85 ≤ 𝑥 < 10.0.23 |
𝑥
= Vulnerable software versions