CVE-2025-66417

Publication date

2026-01-15 16:25:03

Family

GitHub_M

State

PUBLISHED

Description

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.