CVE-2025-24799 SQLi Scanner

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

Published 18 Mar 2025Updated 17 Jun 202611 sources
CVSS 7.5 PoC CANDIDATE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.