SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
CVSS Metrics