CVE-2022-39323 | GLPI up to 10.0.3 API REST user_token sql injection (GHSA-cp6q-9p4x-8hr9 / EUVD-2022-41805)
A vulnerability identified as critical has been detected in GLPI up to 10.0.3. The impacted element is an unknown function of the component API REST Handler. The manipulation of the argument user_token leads to sql injection.
This vulnerability is traded as CVE-2022-39323. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.