Vulnerability Description
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | >= 0.85, < 10.0.18 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-24801?
CVE-2025-24801 is a vulnerability with a CVSS score of 8.5 (HIGH). GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
How severe is CVE-2025-24801?
CVE-2025-24801 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24801?
Check the references section above for vendor advisories and patch information. Affected products include: Glpi-Project Glpi.