← Back to browse · API

CVE-2025-24801

Severity
HIGH
CVSS
8.6
EPSS
0.18319
Risk score
40.81
CISA KEV
No
PoC
No
Published
2025-03-18
Modified
2025-03-18
First seen
2026-08-07
Aliases
EUVD-2025-6705
Products
glpi-project:glpi 0.85, < 10.0.18
Sources
euvd EUVD-2025-6705

Description

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.

References