CVE-2024-45600: Pluginsglpi Fields
High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.
Affected products
- Pluginsglpi Fields: before 1.21.13 (fixed in 1.21.13)
Published 2024-12-26. Last modified 2026-06-17.