CVE-2017-11474: GLPI-Project GLPI

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.

Affected products

Published 2017-07-20. Last modified 2026-06-17.