CVE-2025-66417: GLPI has an unauthenticated SQL injection through the inventory endpoint
Published Jan 15, 2026
·Updated
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.
Affected Software
2 affected components
glpi>11.0.0<=11.0.3
GLPI-PROJECT GLPI>=11.0.0<11.0.3
Event History
Jan 15, 2026
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66417?
CVE-2025-66417 has a high severity level as it allows unauthenticated SQL injection attacks.
2
How do I fix CVE-2025-66417?
To fix CVE-2025-66417, upgrade GLPI to version 11.0.3 or later.
3
What versions of GLPI are affected by CVE-2025-66417?
CVE-2025-66417 affects GLPI versions from 11.0.0 up to, but not including, 11.0.3.
4
What type of attack can CVE-2025-66417 facilitate?
CVE-2025-66417 can facilitate unauthenticated SQL injection attacks through the inventory endpoint.
5
Is user authentication required to exploit CVE-2025-66417?
No, CVE-2025-66417 can be exploited by unauthenticated users.