CVE-2025-21619: GLPI allows SQL injection through the rules configuration
Published Mar 18, 2025
·Updated
GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.
Affected Software
2 affected components
GLPI GLPI<10.0.18
GLPI-PROJECT GLPI>=0.78<10.0.18
Event History
Mar 18, 2025
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21619?
CVE-2025-21619 is a high-severity vulnerability due to SQL injection risk.
2
How do I fix CVE-2025-21619?
You can fix CVE-2025-21619 by upgrading GLPI to version 10.0.18 or later.
3
What can happen if CVE-2025-21619 is exploited?
Exploitation of CVE-2025-21619 can lead to unauthorized database access and potential data manipulation.
4
Who is affected by CVE-2025-21619?
CVE-2025-21619 affects all versions of GLPI prior to 10.0.18.
5
Is there a workaround for CVE-2025-21619?
There is no known workaround for CVE-2025-21619; an update is required to mitigate the vulnerability.