GLPI Inventory Plugin SQL Injection Vulnerability in Reports

Vulnerability

A SQL injection vulnerability has been identified in the GLPI Inventory Plugin, specifically in versions through 1.6.5. The issue arises from the handling of non-sanitized user input in reports, which can be exploited by users with the appropriate rights. This vulnerability has been addressed in version 1.6.6.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries and potentially access or modify sensitive data.

Remediation

Users can upgrade to GLPI Inventory Plugin version 1.6.6 to address this vulnerability.

Added: Mar 18, 2026, 12:46 AM
Updated: Mar 18, 2026, 12:46 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
3.1
exploitability
4.9
remediation
7.7
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.