{"cve":"CVE-2025-24799","enrichment":{"created":"2025-07-13T11:07:10.108461+00:00","updated":"2025-07-13T11:07:10.108539+00:00","vendors":["glpi-project","glpi-project$PRODUCT$glpi"]},"epss":{"score":0.86692},"mitre":{"cpes":[],"created":"2025-03-18T18:27:54.631000+00:00","description":"GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2025/24xxx/CVE-2025-24799.json","references":["https://github.com/glpi-project/glpi/security/advisories/GHSA-jv89-g7f7-jwfg"],"title":"GLPI allows unauthenticated SQL injection through the inventory endpoint","updated":"2025-03-18T18:53:35.088000+00:00","vendors":[],"weaknesses":["CWE-89"]},"nvd":{"cpes":["cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*"],"created":"2025-03-18T19:15:48.927000+00:00","description":"GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2025/CVE-2025-24799.json","references":["https://github.com/glpi-project/glpi/security/advisories/GHSA-jv89-g7f7-jwfg"],"title":null,"updated":"2026-06-17T08:59:37.960000+00:00","vendors":["glpi-project","glpi-project$PRODUCT$glpi"],"weaknesses":["CWE-89"]},"opencve":{"changes":[{"created":"2025-03-18T18:45:00+00:00","data":[{"details":{"new":"GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.","old":null},"type":"description"},{"details":{"new":"GLPI allows unauthenticated SQL injection through the inventory endpoint","old":null},"type":"title"},{"details":{"added":["CWE-89"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/glpi-project/glpi/security/advisories/GHSA-jv89-g7f7-jwfg"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"92073fc0-5b1e-4423-8c78-6a144ddedac8"},{"created":"2025-03-18T19:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"fa019758-8691-4fb5-863a-45d9b4d6705f"},{"created":"2025-07-12T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.61484},"old":{"score":0.60131}}}},"type":"metrics"}],"id":"67ae385a-fe91-43e5-9949-a3f2c5e95609"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.53235},"old":{"score":0.61484}}}},"type":"metrics"}],"id":"39d76c39-7b82-47ea-92e6-e370763246f0"},{"created":"2025-07-31T19:00:00+00:00","data":[{"details":{"added":["cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"059472d9-e7b1-4710-a1de-9b626e0704bc"}],"cpes":{"data":["cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2025-03-18T18:27:54.631000+00:00","provider":"mitre"},"description":{"data":"GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.86692},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/glpi-project/glpi/security/advisories/GHSA-jv89-g7f7-jwfg"],"providers":["mitre","nvd"]},"title":{"data":"GLPI allows unauthenticated SQL injection through the inventory endpoint","provider":"mitre"},"updated":{"data":"2025-07-31T18:45:03.050000+00:00","provider":"nvd"},"vendors":{"data":["glpi-project","glpi-project$PRODUCT$glpi"],"providers":["nvd","enrichment"]},"weaknesses":{"data":["CWE-89"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-03-18T18:27:54.631000+00:00","description":"GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"GLPI allows unauthenticated SQL injection through the inventory endpoint","updated":"2025-03-18T18:53:24+00:00","vendors":[],"vulnrichment_repo_path":"2025/24xxx/CVE-2025-24799.json","weaknesses":[]}}