PT-2026-3063 · Glpi+1 · Glpi+1

CVE-2025-66417

·

Publicado

2026-01-03

·

Atualizado

2026-03-19

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions 11.0.0 through 11.0.2
Description An unauthenticated user can execute SQL injection attacks through the inventory endpoint. The issue affects GLPI versions 11.0.0 through 11.0.2. The vulnerable endpoint is /inventory. The attack leverages a SQL injection flaw, allowing potential unauthorized access or modification of data.
Recommendations Update to version 11.0.3 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05695
CVE-2025-66417
GHSA-P467-682W-9CC9

Produtos afetados

Glpi
Red Os