CVE-2025-21619

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21619
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21619.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-21619
Aliases
  • GHSA-pcmc-xv3g-hjxv
Downstream
Published
2025-03-18T18:25:13Z
Modified
2025-10-21T19:32:21Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
GLPI allows SQL injection through the rules configuration
Details

GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/glpi-project/glpi

Affected ranges

Type
GIT
Repo
https://github.com/glpi-project/glpi
Events