CVE-2025-24801
largeAuthenticated PHP File Upload RCE in GLPI Asset Management
GLPI, a free open-source IT asset and service management platform, is vulnerable to an unrestricted file upload flaw (CWE-434) that lets an authenticated user upload *.php files to the GLPI server and force their execution. The flaw is triggered over the network and requires only low-privilege (i.e., any valid) user credentials, with no user interaction needed. Successful exploitation results in remote code execution with the web server's privileges, with high impact on confidentiality, integrity, and availability of the GLPI instance and potentially the underlying host. All GLPI deployments running versions prior to 10.0.18 are affected, and the issue is fixed in GLPI 10.0.18. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 21% probability of exploitation within 30 days (97th percentile), indicating elevated risk despite the absence of CISA KEV listing.
What to do: Upgrade to GLPI 10.0.18 as soon as possible. Until patched, prevent PHP execution in GLPI's upload/files directories via web-server configuration (e.g., disable PHP handling for those paths) and audit upload directories and access logs for unexpected .php files. Because any authenticated account can exploit this, review accounts for suspicious activity and rotate credentials for accounts that may have been compromised.
| glpi-project GLPI | prior to 10.0.18 (fixed in 10.0.18) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
- Vendors
- glpi-project
- Products
- glpi
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.