https://reddit.com/r/netsec/comments/1j9hcdw/preauthentication_sql_injection_to_rce_in_glpi/: Pre-authentication SQL injection to RCE in GLPI (CVE-2025-24799/CVE-2025-24801)
Published Mar 12, 2025
·Updated
Affected Software
1 affected component
GLPI GLPI
Frequently Asked Questions
1
What is the severity of CVE-2025-24799 and CVE-2025-24801?
CVE-2025-24799 and CVE-2025-24801 are considered critical vulnerabilities due to their potential for remote code execution.
2
How do I fix CVE-2025-24799 and CVE-2025-24801?
To remediate CVE-2025-24799 and CVE-2025-24801, users should update to the latest version of GLPI as provided by official sources.
3
What type of vulnerability is CVE-2025-24799?
CVE-2025-24799 is a pre-authentication SQL injection vulnerability that could allow attackers to compromise the system.
4
Can CVE-2025-24801 be exploited remotely?
Yes, CVE-2025-24801 can be exploited remotely without needing authentication, posing a significant security risk.
5
Is there a known exploit for CVE-2025-24799?
Yes, there are known exploits for CVE-2025-24799 that allow attackers to execute arbitrary code on affected systems.