ZeroHour

CVE-2025-24801

large

Authenticated PHP File Upload RCE in GLPI Asset Management

CVSS 3.1
8.8 high
EPSS
21%p97
Published
()
Modified
AI analysis

GLPI, a free open-source IT asset and service management platform, is vulnerable to an unrestricted file upload flaw (CWE-434) that lets an authenticated user upload *.php files to the GLPI server and force their execution. The flaw is triggered over the network and requires only low-privilege (i.e., any valid) user credentials, with no user interaction needed. Successful exploitation results in remote code execution with the web server's privileges, with high impact on confidentiality, integrity, and availability of the GLPI instance and potentially the underlying host. All GLPI deployments running versions prior to 10.0.18 are affected, and the issue is fixed in GLPI 10.0.18. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 21% probability of exploitation within 30 days (97th percentile), indicating elevated risk despite the absence of CISA KEV listing.

What to do: Upgrade to GLPI 10.0.18 as soon as possible. Until patched, prevent PHP execution in GLPI's upload/files directories via web-server configuration (e.g., disable PHP handling for those paths) and audit upload directories and access logs for unexpected .php files. Because any authenticated account can exploit this, review accounts for suspicious activity and rotate credentials for accounts that may have been compromised.

Affected
glpi-project GLPIprior to 10.0.18 (fixed in 10.0.18)
Estimated exposure
largetens of thousands of internet-exposed GLPI instances (GLPI is widely deployed by organizations managing IT assets) — GLPI is one of the most widely adopted free open-source IT asset/ITSM platforms, with a large global self-hosted install base concentrated in helpdesk and asset-management deployments, and public internet scans routinely surface tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.

Vendors
glpi-project
Products
glpi
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.