CVE Feed

    Dashboard / CVE / CVE-2026-11321

    CVE-2026-11321

    The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection. An authenticated user with access to the Data injection feature can embed SQL expressions such as SLEEP() in a mapped field (for example Serial Number) to manipulate the generated query and extract database information via time-based blind injection.

    Published:Jul 10, 2026
    Last Modified:Jul 14, 2026
    EPS:Jul 10, 2026
    EPSS Score:0.00314
    CVSS Score:6.4

    Affected Products

    Vendor
    Pluginsglpi
    Product
    Datainjection

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High