CVE-2017-11329: GLPI-Project GLPI

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.

Affected products

Published 2017-07-17. Last modified 2026-06-17.