← Vulnerability feed

Vulnerability record · CVE-2022-31061 · published 28 June 2022

CVE-2022-31061: GLPI unauthenticated SQL injection on login page

Glpi Project · Glpi

GLPI contains a SQL injection flaw reachable from the login page. Because no credentials are needed, any network attacker can attempt to inject SQL before authenticating. The vendor states there are no known workarounds, so upgrading is the only fix.

9.8 CVSS 3.1 Critical EPSS 51% · top 1.1% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8 and high EPSS makes this an urgent patch target despite no KEV listing.

What it is

GLPI contains a SQL injection flaw reachable from the login page. Because no credentials are needed, any network attacker can attempt to inject SQL before authenticating. The vendor states there are no known workarounds, so upgrading is the only fix.

Impact

An attacker can read and modify database contents and potentially disrupt the application, given the high confidentiality, integrity and availability impact in the CVSS vector. Full compromise of the GLPI database is the realistic worst case.

Attack surface

Reachable over the network via the login page with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or intranet-exposed GLPI instance is in scope.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation attempts. References are patch and advisory links only, with no public exploit tag.

What to do

  • Upgrade GLPI to a version containing the fix in commit 21ae07d00d0b3230f6235386e98388cfc5bb0514 as soon as possible.
  • If immediate upgrade is impossible, restrict network access to the GLPI login page to trusted networks or place it behind an authenticating reverse proxy.
  • Review database logs and application logs for anomalous SQL or error patterns originating from the login endpoint.
  • Rotate database credentials and any secrets stored in GLPI after patching, in case of prior compromise.
  • Monitor the vendor advisory GHSA-w2gc-v2gm-q7wq for updated guidance, since no workaround exists.

Detection

  • Inspect web server and WAF logs for SQL metacharacters or injection patterns in requests to the GLPI login endpoint.
  • Alert on database errors or unusual query volume correlated with login page requests.
  • Baseline normal login page request parameters and flag deviations, especially unexpected SQL keywords.
  • Review GLPI application logs for authentication or database exceptions occurring without a preceding successful login.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31061 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2025-24799GLPI unauthenticated SQL injection in inventory endpointGLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issu…EPSS 87%analysed9.8CVE-2023-46727GLPI inventory endpoint SQL injectionGLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authent…EPSS 68%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 0.85%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2022-31061), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.