CVE-2025-66417
HIGHGLPI 11.0.0-11.0.2 - Unauthenticated SQL Injection via Inventory Endpoint
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-66417. PoCs published by lem0naids, nflatrea.
AI-analyzed exploit summary This PoC demonstrates a blind SQL injection vulnerability in the `deviceid` parameter of an XML-based API endpoint. The payload uses `EXTRACTVALUE` to exfiltrate the database name via error-based techniques.
Description
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.
Exploits (2)
This PoC demonstrates a blind SQL injection vulnerability in the `deviceid` parameter of an XML-based API endpoint. The payload uses `EXTRACTVALUE` to exfiltrate the database name via error-based techniques.
This repository contains a functional Python script that exploits CVE-2025-66417, a blind SQL injection vulnerability in GLPI's inventory endpoint. The exploit sends a malformed XML payload to trigger the SQL injection and retrieve database information.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N