← Vulnerability feed

Vulnerability record · CVE-2024-29889 · published 7 May 2024

CVE-2024-29889: GLPI saved searches SQL injection allows account takeover

Glpi Project · Glpi

GLPI before 10.0.15 contains a SQL injection flaw in the saved searches feature. An authenticated user can inject SQL to modify another user's account data and take control of that account. Because GLPI is an asset and IT management system, a compromised account can expose managed inventory and administrative functions.

8.1 CVSS 3.1 High EPSS 63% · top 0.8% CWE-89 · SQL injection
8.1CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityHigh CVSS (8.1) and very high EPSS (0.6296) indicate likely exploitation, though it requires an authenticated low-privileged account and is not in KEV.

What it is

GLPI before 10.0.15 contains a SQL injection flaw in the saved searches feature. An authenticated user can inject SQL to modify another user's account data and take control of that account. Because GLPI is an asset and IT management system, a compromised account can expose managed inventory and administrative functions.

Impact

An attacker with a low-privileged authenticated account can alter another user's account data and seize control of it, gaining that user's access and privileges. The CVSS vector shows high confidentiality and integrity impact with no availability impact.

Attack surface

Reachable over the network through the saved searches feature; the attacker must be authenticated with a low-privileged account and no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N).

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at 0.6296 (99.2nd percentile), and references are limited to the patch and vendor advisory with no public exploit tag.

What to do

  • Upgrade GLPI to 10.0.15 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict or disable the saved searches feature for untrusted accounts.
  • Review and minimize authenticated accounts, removing or disabling unused ones to reduce the pool of exploitable sessions.
  • Audit user account records for unexpected changes and reset credentials of any accounts suspected of tampering.
  • Monitor GLPI logs for anomalous saved search activity from low-privileged users.

Detection

  • Review GLPI application and database logs for SQL error patterns or unusual queries originating from the saved searches feature.
  • Alert on saved search creation or modification events by users who do not normally use the feature.
  • Monitor for account data changes, especially email or password changes, made by accounts other than the account owner.
  • Correlate authentication events with subsequent account modification activity for the same session.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-29889 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2025-24799GLPI unauthenticated SQL injection in inventory endpointGLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issu…EPSS 87%analysed9.8CVE-2023-46727GLPI inventory endpoint SQL injectionGLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authent…EPSS 68%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 0.85%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2024-29889), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.