Vulnerability record · CVE-2025-24799 · published 18 March 2025
CVE-2025-24799: GLPI unauthenticated SQL injection in inventory endpoint
Glpi Project · Glpi
GLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issue is fixed in version 10.0.18. Because the endpoint is unauthenticated and the injection is straightforward, this is a serious pre-auth database compromise risk for exposed GLPI instances.
Description
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8 and very high EPSS makes this an urgent patch-first issue for any exposed GLPI instance.
What it is
GLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issue is fixed in version 10.0.18. Because the endpoint is unauthenticated and the injection is straightforward, this is a serious pre-auth database compromise risk for exposed GLPI instances.
Impact
An attacker can inject arbitrary SQL against the GLPI database, potentially reading, modifying, or deleting data and, depending on database privileges, executing database-level operations. This can expose credentials, inventory data, and other sensitive records managed by GLPI.
Attack surface
The flaw is reached over the network via the inventory endpoint, requiring no authentication and no user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed GLPI instance with the inventory endpoint reachable is in scope.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is very high (0.86348, 99.7th percentile), indicating elevated likelihood of exploitation activity. The only reference is the vendor advisory, so no public exploit details are confirmed in this record.
What to do
- Upgrade GLPI to 10.0.18 or later immediately.
- If immediate upgrade is not possible, restrict network access to the inventory endpoint to trusted inventory sources only.
- Place GLPI behind a reverse proxy or WAF and block or inspect requests to the inventory endpoint that contain SQL metacharacters.
- Run the GLPI database account with least privilege, avoiding administrative database rights.
- Audit database and web logs for anomalous queries or requests to the inventory endpoint.
Detection
- Monitor web server and application logs for requests to the GLPI inventory endpoint containing SQL keywords, quotes, or comment sequences.
- Alert on database errors or unusual query patterns originating from the GLPI application account.
- Baseline normal inventory endpoint traffic and flag deviations in request size, parameters, or source IPs.
- Review GLPI database audit logs for unexpected reads or writes to sensitive tables.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/glpi-project/glpi/security/advisories/GHSA-jv89-g7f7-jwfg | Vendor Advisory |
Track CVE-2025-24799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24799), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.