CVE-2024-56801: Infotel Tasklists

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.

Affected products

  • Infotel Tasklists: before 2.0.4 (fixed in 2.0.4)

Published 2024-12-30. Last modified 2026-06-17.