CVE-2025-24799
18.03.2025, 19:15
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
Vendor | Product | Version |
---|---|---|
glpi-project | glpi | 10.0.0 ≤ 𝑥 < 10.0.18 |
𝑥
= Vulnerable software versions