The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php (CVE-2018-13049).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0330.json"