GLPI ITSM Tool Flaw Allows Attackers to Inject Malicious SQL Queries

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

GLPI ITSM Tool Flaw Allows Attackers to Inject Malicious SQL Queries

Post by Shane1145 »

A critical SQL injection vulnerability, tracked as CVE-2025-24799, has been identified in GLPI, a widely used open-source IT Service Management (ITSM) tool.

The flaw, if exploited, enables remote, unauthenticated attackers to manipulate database queries, potentially leading to severe consequences such as data theft, tampering, or even remote code execution.


https://gbhackers.com/glpi-itsm-tool-flaw/
Post Reply