PT-2025-7036 · Glpi+1 · Glpi+1

Published

2025-01-23

·

Updated

2026-02-16

·

CVE-2025-24799

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.18
Description GLPI is an asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This allows an attacker to execute arbitrary SQL commands. A major data breach at Eurofiber France, impacting over 3,600 clients including Thales, Orange, and French ministries, was attributed to exploitation of this flaw. The vulnerability is exploitable through the /inventory API endpoint, where the input to SQL queries is not properly sanitized. The inventory endpoint is vulnerable to SQL injection due to improper handling of user-supplied data.
Recommendations Update GLPI to version 10.0.18 or later.

Exploit

Fix

SQL injection

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-4115
BDU:2025-03181
BDU:2025-03182
CVE-2025-24799
GHSA-JV89-G7F7-JWFG

Affected Products

Alt Linux
Glpi