← back
CVE-2025-24799highobserved exploitationCWE-89

GLPI allows unauthenticated SQL injection through the inventory endpoint

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.5epss 86%
from disclosure to weapon16 days
Published on NVDMar 18
1st PoC+16d
metasploitMar 12
VulnCheck+30d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
glpi-project · glpi
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.