RULE(RULE ID:338785)

Rule General Information
Release Date: 2025-04-08
Rule Name: GLPI Pre-Auth SQL Injection Vulnerability (CVE-2025-24799)
Severity:
CVE ID:
Rule Protection Details
Description: GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://github.com/glpi-project/glpi/security/advisories/GHSA-jv89-g7f7-jwfg
https://access.redhat.com/security/cve/cve-2025-24799
Solutions
Refer to the announcement or patch by the vendor: https://github.com/glpi-project/glpi/security/advisories/GHSA-jv89-g7f7-jwfg