PT-2024-10112 · Glpi+2 · Glpi+2

·

CVE-2024-41679

·

Published

2024-11-15

·

Updated

2025-08-13

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.17
Description The issue is related to a SQL injection vulnerability in the ticket form of GLPI, a free asset and IT management software package. An authenticated user can exploit this vulnerability, potentially allowing a remote attacker to perform SQL injections. The vulnerability is due to a lack of protection measures for the SQL query structure.
Recommendations For versions prior to 10.0.17, upgrade to version 10.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the ticket form until the upgrade is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-1277
BDU:2025-00336
CVE-2024-41679
GHSA-HQ9Q-JFHP-QQGM

Affected Products

Alt Linux
Glpi
Red Os