First published: Tue Mar 18 2025(Updated: )
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | <10.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24801 is considered a high-severity vulnerability due to its potential for unauthorized execution of PHP files.
To fix CVE-2025-24801, you should upgrade to GLPI version 10.0.18 or later.
CVE-2025-24801 is a remote code execution vulnerability affecting GLPI.
Any authenticated user of GLPI versions prior to 10.0.18 is affected by CVE-2025-24801.
In addition to upgrading, restricting user permissions and file upload capabilities can help mitigate CVE-2025-24801.