← Vulnerability feed

Vulnerability record · CVE-2024-27096 · published 18 March 2024

CVE-2024-27096: GLPI search engine SQL injection by authenticated user

Glpi Project · Glpi

GLPI, a free asset and IT management package, contains a SQL injection flaw in its search engine. An authenticated user can exploit it to extract data from the underlying database. The issue is patched in version 10.0.13.

6.5 CVSS 3.1 Medium EPSS 59% · top 0.9% CWE-89 · SQL injection
6.5CVSS 3.1 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in the search engine to extract data from the database. This issue has been patched in version 10.0.13.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable by any authenticated user with high confidentiality impact and a very high EPSS percentile, though it is not known to be actively exploited.

What it is

GLPI, a free asset and IT management package, contains a SQL injection flaw in its search engine. An authenticated user can exploit it to extract data from the underlying database. The issue is patched in version 10.0.13.

Impact

An attacker with a valid account gains read access to database contents beyond what their role should allow, with high confidentiality impact but no integrity or availability effect.

Attack surface

Reachable over the network through the GLPI search engine; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N), so any authenticated account is sufficient.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.58818 (99th percentile), indicating elevated predicted exploitation activity.

What to do

  • Upgrade GLPI to version 10.0.13 or later, which contains the patch commit 61a0c2302b4f633f5065358adc36058e1abc37f9.
  • If immediate upgrade is not possible, restrict and review accounts with access to the search engine and remove unused or stale users.
  • Apply least-privilege database credentials for the GLPI service account to limit what a successful injection can read.
  • Monitor vendor advisory GHSA-2x8m-vrcm-2jqv for any further guidance.

Detection

  • Review GLPI and database logs for anomalous search queries containing SQL metacharacters such as quotes, UNION, or comment sequences.
  • Alert on database queries from the GLPI service account that read tables or columns outside normal application behavior.
  • Baseline normal search engine request patterns per user and flag deviations in volume or parameter structure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27096 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2025-24799GLPI unauthenticated SQL injection in inventory endpointGLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issu…EPSS 87%analysed9.8CVE-2023-46727GLPI inventory endpoint SQL injectionGLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authent…EPSS 68%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 0.85%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2024-27096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.