First published: Tue Mar 18 2025(Updated: )
GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | <10.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-21619 is a high-severity vulnerability due to SQL injection risk.
You can fix CVE-2025-21619 by upgrading GLPI to version 10.0.18 or later.
Exploitation of CVE-2025-21619 can lead to unauthorized database access and potential data manipulation.
CVE-2025-21619 affects all versions of GLPI prior to 10.0.18.
There is no known workaround for CVE-2025-21619; an update is required to mitigate the vulnerability.