SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter. Upstream bug: https://github.com/glpi-project/glpi/issues/2449 Upstream patch: https://github.com/glpi-project/glpi/commit/32fd946c8c1c52a7545bf76030bf3bfa4f6b80e2
Created glpi tracking bugs for this issue: Affects: epel-7 [bug 1476171] Affects: fedora-all [bug 1476172]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.