Security Advisory
CVE-2025-66417
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.