Sploitus

CVE-2025-66417

1 known exploit for CVE-2025-66417

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

Affected products
Glpi, Red Os
Glpi-project Glpi
< 11.0.3
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.4% (37th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2026-01-15
CVE-2025-66417 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-66417

Proof-of-concept code and exploit modules indexed by Sploitus