CVE-2017-11329: GLPI-Project GLPI
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
Affected products
- GLPI-Project GLPI: up to and including 9.1.4
Published 2017-07-17. Last modified 2026-06-17.