CVE-2025-24799: GLPI allows unauthenticated SQL injection through the inventory endpoint
Published Mar 18, 2025
·Updated
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
Affected Software
2 affected components
GLPI GLPI<10.0.18
GLPI-PROJECT GLPI>=10.0.0<10.0.18
Event History
Mar 18, 2025
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 14, 2026
News Published
via BleepingComputer·04:02 PM
Feb 16, 2026
News Published
via BleepingComputer·04:06 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-24799?
CVE-2025-24799 has been classified as a critical severity vulnerability due to the potential for unauthorized SQL injection attacks.
2
How do I fix CVE-2025-24799?
To fix CVE-2025-24799, upgrade to GLPI version 10.0.18 or later.
3
What systems are affected by CVE-2025-24799?
CVE-2025-24799 affects versions of GLPI prior to 10.0.18.
4
Can unauthenticated users exploit CVE-2025-24799?
Yes, CVE-2025-24799 can be exploited by unauthenticated users via the inventory endpoint.
5
What type of vulnerability is CVE-2025-24799?
CVE-2025-24799 is a SQL injection vulnerability.