← Back to browse · API

CVE-2025-24799

Severity
HIGH
CVSS
7.5
EPSS
0.86067
Risk score
60.12
CISA KEV
No
PoC
No
Published
2025-03-18
Modified
2025-03-18
First seen
2026-08-07
Aliases
EUVD-2025-6704
Products
glpi-project:glpi 10.0.0, < 10.0.18
Sources
euvd EUVD-2025-6704

Description

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

References