GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Aug 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Mar 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18. | |
| Title | GLPI allows authenticated remote code execution | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-18T18:32:06.401Z
Updated: 2025-03-18T18:51:51.204Z
Reserved: 2025-01-23T17:11:35.838Z
Link: CVE-2025-24801
Updated: 2025-03-18T18:50:20.690Z
Status : Analyzed
Published: 2025-03-18T19:15:49.110
Modified: 2025-08-01T00:57:21.037
Link: CVE-2025-24801
No data.