← Vulnerability feed

Vulnerability record · CVE-2025-24799 · published 18 March 2025

CVE-2025-24799: GLPI unauthenticated SQL injection in inventory endpoint

Glpi Project · Glpi

GLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issue is fixed in version 10.0.18. Because the endpoint is unauthenticated and the injection is straightforward, this is a serious pre-auth database compromise risk for exposed GLPI instances.

9.8 CVSS 3.1 Critical EPSS 87% · top 0.3% CWE-89 · SQL injection
9.8CVSS 3.1 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8 and very high EPSS makes this an urgent patch-first issue for any exposed GLPI instance.

What it is

GLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issue is fixed in version 10.0.18. Because the endpoint is unauthenticated and the injection is straightforward, this is a serious pre-auth database compromise risk for exposed GLPI instances.

Impact

An attacker can inject arbitrary SQL against the GLPI database, potentially reading, modifying, or deleting data and, depending on database privileges, executing database-level operations. This can expose credentials, inventory data, and other sensitive records managed by GLPI.

Attack surface

The flaw is reached over the network via the inventory endpoint, requiring no authentication and no user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed GLPI instance with the inventory endpoint reachable is in scope.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is very high (0.86348, 99.7th percentile), indicating elevated likelihood of exploitation activity. The only reference is the vendor advisory, so no public exploit details are confirmed in this record.

What to do

  • Upgrade GLPI to 10.0.18 or later immediately.
  • If immediate upgrade is not possible, restrict network access to the inventory endpoint to trusted inventory sources only.
  • Place GLPI behind a reverse proxy or WAF and block or inspect requests to the inventory endpoint that contain SQL metacharacters.
  • Run the GLPI database account with least privilege, avoiding administrative database rights.
  • Audit database and web logs for anomalous queries or requests to the inventory endpoint.

Detection

  • Monitor web server and application logs for requests to the GLPI inventory endpoint containing SQL keywords, quotes, or comment sequences.
  • Alert on database errors or unusual query patterns originating from the GLPI application account.
  • Baseline normal inventory endpoint traffic and flag deviations in request size, parameters, or source IPs.
  • Review GLPI database audit logs for unexpected reads or writes to sensitive tables.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-24799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2023-46727GLPI inventory endpoint SQL injectionGLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authent…EPSS 68%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 1.0%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 1.1%9.8CVE-2023-41320Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 35%

Source: NIST National Vulnerability Database (record CVE-2025-24799), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.