CVE-2025-24799 | GLPI up to 10.0.17 Inventory Endpoint sql injection (GHSA-jv89-g7f7-jwfg / Nessus ID 237566)
A vulnerability classified as critical has been found in GLPI up to 10.0.17. This affects an unknown part of the component Inventory Endpoint. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-24799. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.