GLPI SQL Injection Vulnerability in Rules Configuration Forms

Vulnerability

A SQL injection vulnerability has been identified in GLPI, a free asset and IT management software, affecting versions 0.78 and later. This vulnerability allows an administrator user to perform SQL injection through the rules configuration forms.

Impact

Exploitation of this vulnerability allows for SQL injection, which could lead to unauthorized data access or manipulation in the database.

Remediation

Users are advised to upgrade to GLPI version 10.0.18.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.