CVE-2025-24799
GLPI allows unauthenticated SQL injection through the inventory endpoint
Description
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
In plain language
AI Act nowGLPI versions before 10.0.18 let an outsider read information from its database, so small businesses using GLPI should update promptly.
Unauthenticated SQL injection (CWE-89) in the GLPI inventory endpoint can expose database contents over the network.
What to do now
- Check whether you run GLPI and confirm its installed version.
- Upgrade GLPI to version 10.0.18.
- If the upgrade must wait, restrict access to the inventory endpoint to trusted systems.
- Review database and web-server logs for unusual inventory-endpoint requests.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-24799 and every CVE in our database. Create a free account — no credit card required.
Create Free Account