A critical vulnerability in GLPI, a widely-used open-source IT Service Management (ITSM) platform tracked as CVE-2025-24799, enables unauthenticated attackers to perform SQL injection attacks through the inventory endpoint. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Given that successful exploitation would enable remote attackers to run arbitrary SQL statements on the compromised system, this vulnerability is categorized as having a “High” severity. The attack could allow unauthorized access to sensitive data and, under certain conditions, enable attackers to write and execute arbitrary code on affected servers. Organizations using GLPI should prioritize this update to protect critical IT assets and sensitive information from this significant security threat. This flaw can lead to remote code execution (RCE), potentially resulting in a complete system compromise of the affected IT Service Management platform. Organizations utilizing this popular asset management solution are strongly advised to update immediately to version 10.0.18, which contains the necessary security patches. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. This component, used for inventory purposes, processes HTTP requests without proper validation, allowing attackers to inject malicious SQL commands.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 28 Mar 2025 10:45:16 +0000