CVE-2025-24801: GLPI allows authenticated remote code execution
Published Mar 18, 2025
·Updated
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of .php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
Affected Software
2 affected components
GLPI GLPI<10.0.18
GLPI-PROJECT GLPI>=0.85<10.0.18
Event History
Mar 18, 2025
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24801?
CVE-2025-24801 is considered a high-severity vulnerability due to its potential for unauthorized execution of PHP files.
2
How do I fix CVE-2025-24801?
To fix CVE-2025-24801, you should upgrade to GLPI version 10.0.18 or later.
3
What type of vulnerability is CVE-2025-24801?
CVE-2025-24801 is a remote code execution vulnerability affecting GLPI.
4
Who is affected by CVE-2025-24801?
Any authenticated user of GLPI versions prior to 10.0.18 is affected by CVE-2025-24801.
5
What actions can be taken to mitigate CVE-2025-24801?
In addition to upgrading, restricting user permissions and file upload capabilities can help mitigate CVE-2025-24801.