← Vulnerability feed

Vulnerability record · CVE-2024-31456 · published 7 May 2024

CVE-2024-31456: GLPI map search SQL injection allows authenticated data theft

Glpi Project · Glpi

GLPI before 10.0.15 contains a SQL injection flaw reachable from the map search feature. An authenticated user can inject SQL through that search path, and the vendor has fixed it in 10.0.15. Because GLPI stores asset and IT management data, a successful injection can expose sensitive records.

6.5 CVSS 3.1 Medium EPSS 59% · top 0.9% CWE-89 · SQL injection
6.5CVSS 3.1 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. This vulnerability is fixed in 10.0.15.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable by any authenticated user with high confidentiality impact, and EPSS is very high at the 99th percentile even though it is not in KEV.

What it is

GLPI before 10.0.15 contains a SQL injection flaw reachable from the map search feature. An authenticated user can inject SQL through that search path, and the vendor has fixed it in 10.0.15. Because GLPI stores asset and IT management data, a successful injection can expose sensitive records.

Impact

An attacker with a valid account gains read access to data behind the vulnerable query, with high confidentiality impact. Integrity and availability are not affected per the CVSS vector.

Attack surface

The flaw is network-reachable via the map search functionality and requires a low-privileged authenticated account; no user interaction is needed per the CVSS vector.

Exploitation

No public exploitation is confirmed in the record: CISA KEV does not list it, and references are limited to the patch and vendor advisory. EPSS is high at 0.59136 (99th percentile), indicating elevated predicted exploitation likelihood.

What to do

  • Upgrade GLPI to 10.0.15 or later, applying the vendor patch commit.
  • If immediate upgrade is not possible, restrict access to the map search feature and limit accounts to only the privileges they require.
  • Review GLPI accounts for unnecessary or stale users and remove them to reduce the authenticated attack surface.
  • Monitor the vendor advisory GHSA-gcj4-2cp3-6h5j for any updated guidance.

Detection

  • Inspect web and application logs for SQL metacharacters or unusual query patterns in requests to map search endpoints.
  • Alert on anomalous database query volume or errors originating from GLPI application accounts.
  • Baseline normal map search usage and flag deviations from authenticated accounts, especially low-privilege ones.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-31456 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2025-24799GLPI unauthenticated SQL injection in inventory endpointGLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issu…EPSS 87%analysed9.8CVE-2023-46727GLPI inventory endpoint SQL injectionGLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authent…EPSS 68%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 0.85%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2024-31456), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.