CVE 7.5 HIGH

GLPI Inventory Plugin is Vulnerable to Unauthenticated SQL Injection_CVE-2025-32786

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Versions 1.5.0 and below are vulnerable to SQL Injection. This issue is fixed in version 1.5.1.

Basic Information

ID CVE-2025-32786
Source GitHub_M
Published Nov 4, 2025 at 20:18

Affected Product

Vendor glpi-project
Product glpi-inventory-plugin
Version < 1.5.1
Affected Versions glpi-project glpi-inventory-plugin < 1.5.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.