CVE-2024-41679: GLPI-Project GLPI
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.
Affected products
- GLPI-Project GLPI: from 10.0.0, before 10.0.17 (fixed in 10.0.17)
Published 2024-11-15. Last modified 2026-06-17.