GLPI versions 0.80 through 10.0.7 contain an SQL injection vulnerability in the Computer Virtual Machine form and GLPI inventory request functionality. Crafted input submitted through either affected feature can be used to inject SQL commands into backend database queries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2023-36808 affecting GLPI versions prior to 10.0.10. It contains three files: a README describing the vulnerability and usage, a requirements.txt listing the requests dependency, and exploit.py as the sole executable component. The exploit targets the unauthenticated GLPI XML inventory endpoint at /front/inventory.php. It sends POST requests with Content-Type: application/xml and injects SQL through the <deviceid> element. The injected expression uses a UNION SELECT IF(condition,SLEEP(delay),0) pattern to implement time-based blind SQL injection. The script first checks reachability, then verifies the injection by comparing timing behavior for true and false conditions. Its main capability is database extraction rather than code execution. It uses binary search on LENGTH() and ASCII(SUBSTR()) to recover query output efficiently, reducing the number of requests per character compared with naive brute force. By default it enumerates the number of rows in glpi_users and extracts each user's name, password, and personal_token fields. It also supports a --query option to extract the result of an arbitrary SQL query supplied by the operator. Timing parameters are tunable with --sleep, and request concurrency is limited with a semaphore via --parallel to reduce timing noise. The code structure is straightforward: _post() sends the XML request and measures elapsed time; check() evaluates a boolean SQL condition; extract_length(), extract_char(), and extract_string() recover query results; check_target() validates endpoint reachability; verify_injection() confirms the vulnerability; dump_users() performs the default credential/token dump; and main() parses arguments and orchestrates exploitation. Overall, this is a real, functional unauthenticated web/network SQLi exploit focused on blind data extraction from vulnerable GLPI instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.