CVE-2025-24799 SQLi Scanner

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

Published 18 Mar 2025Updated 17 Jun 202611 sources
CVSS 7.5 PoC CANDIDATE

Source timeline

Discovered through PoC-in-GitHubView source ↗
CVE record published by NVDView source ↗