Vulnerability record · CVE-2024-29889 · published 7 May 2024
CVE-2024-29889: GLPI saved searches SQL injection allows account takeover
Glpi Project · Glpi
GLPI before 10.0.15 contains a SQL injection flaw in the saved searches feature. An authenticated user can inject SQL to modify another user's account data and take control of that account. Because GLPI is an asset and IT management system, a compromised account can expose managed inventory and administrative functions.
Description
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Automated analysis
high priorityHigh CVSS (8.1) and very high EPSS (0.6296) indicate likely exploitation, though it requires an authenticated low-privileged account and is not in KEV.
What it is
GLPI before 10.0.15 contains a SQL injection flaw in the saved searches feature. An authenticated user can inject SQL to modify another user's account data and take control of that account. Because GLPI is an asset and IT management system, a compromised account can expose managed inventory and administrative functions.
Impact
An attacker with a low-privileged authenticated account can alter another user's account data and seize control of it, gaining that user's access and privileges. The CVSS vector shows high confidentiality and integrity impact with no availability impact.
Attack surface
Reachable over the network through the saved searches feature; the attacker must be authenticated with a low-privileged account and no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at 0.6296 (99.2nd percentile), and references are limited to the patch and vendor advisory with no public exploit tag.
What to do
- Upgrade GLPI to 10.0.15 or later, which contains the fix.
- If immediate upgrade is not possible, restrict or disable the saved searches feature for untrusted accounts.
- Review and minimize authenticated accounts, removing or disabling unused ones to reduce the pool of exploitable sessions.
- Audit user account records for unexpected changes and reset credentials of any accounts suspected of tampering.
- Monitor GLPI logs for anomalous saved search activity from low-privileged users.
Detection
- Review GLPI application and database logs for SQL error patterns or unusual queries originating from the saved searches feature.
- Alert on saved search creation or modification events by users who do not normally use the feature.
- Monitor for account data changes, especially email or password changes, made by accounts other than the account owner.
- Correlate authentication events with subsequent account modification activity for the same session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-29889 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-29889), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.