Vulnerability CVE-2025-24801: Information
Description
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glpi | sisyphus | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4052-1 | 377585 | Fixed |
glpi | sisyphus_e2k | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4342-1 | - | Fixed |
glpi | sisyphus_riscv64 | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4139-1 | - | Fixed |
glpi | sisyphus_loongarch64 | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4148-1 | - | Fixed |
glpi | p11 | 10.0.18-alt1 | 10.0.18-alt1 | ALT-PU-2025-4115-2 | 377682 | Fixed |