Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-37148

CVE-2024-37148: Glpi-project Glpi SQLi Vulnerability

CVE-2024-37148 is a SQL injection flaw in Glpi-project Glpi that allows authenticated users to alter other user accounts and take control. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2024-37148 Overview

CVE-2024-37148 is an authenticated SQL injection vulnerability in GLPI, an open-source IT asset and service desk management platform. The flaw resides in several AJAX scripts that fail to properly sanitize user-supplied input before including it in SQL queries. An authenticated attacker can inject malicious SQL to modify another user's account data and take over the account. The vulnerability is tracked under CWE-89 and is addressed in GLPI version 10.0.16.

Critical Impact

Authenticated attackers can hijack arbitrary GLPI user accounts, including administrative accounts, by leveraging SQL injection to overwrite account credentials or attributes.

Affected Products

  • GLPI versions prior to 10.0.16
  • Deployments exposing AJAX endpoints to authenticated users
  • Self-hosted GLPI instances used for ITIL service desk, license tracking, and software auditing

Discovery Timeline

  • 2024-07-10 - CVE-2024-37148 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-37148

Vulnerability Analysis

The vulnerability is a SQL injection flaw (CWE-89) reachable through authenticated AJAX endpoints in GLPI. The affected scripts accept parameters that are concatenated into SQL statements without adequate parameterization or escaping. An authenticated user, including a low-privileged one, can craft input that breaks out of the intended query context and executes attacker-controlled SQL against the GLPI database.

Because GLPI stores user credentials, roles, and session-related attributes in the same database, an attacker can update rows belonging to other users. This enables account takeover, including changing passwords, email addresses, or profile associations tied to privileged accounts.

The EPSS percentile of 97.246 indicates that this issue is among the most likely CVEs to see exploitation attempts based on observable characteristics.

Root Cause

The root cause is improper neutralization of special elements in SQL queries constructed inside AJAX handler scripts. User input flows into query strings without prepared statements or parameter binding, allowing attacker-supplied SQL fragments to alter query semantics.

Attack Vector

Exploitation requires network access to the GLPI application and valid authenticated credentials. The attacker submits crafted parameters to a vulnerable AJAX endpoint over HTTP or HTTPS. No user interaction is required beyond the attacker's own authenticated session. Successful exploitation results in unauthorized modification of other users' records and full takeover of targeted accounts.

See the GLPI security advisory GHSA-p626-hph9-p6fj for vendor details.

Detection Methods for CVE-2024-37148

Indicators of Compromise

  • Unexpected UPDATE or INSERT statements against the glpi_users table in database audit logs
  • HTTP requests to /ajax/ endpoints containing SQL metacharacters such as ', --, UNION, or SELECT
  • Password or email changes on user accounts without matching audit trail entries in GLPI's history log
  • Sessions originating from unusual IP addresses that immediately access administrative functions after authentication

Detection Strategies

  • Enable database query logging and alert on parameterized-query violations targeting glpi_users or authentication-related tables
  • Deploy a web application firewall (WAF) with signatures for SQL injection patterns against GLPI AJAX paths
  • Correlate GLPI application logs with authentication events to identify anomalous account modifications performed by non-administrative users

Monitoring Recommendations

  • Monitor the /ajax/ route in HTTP access logs for encoded SQL payloads and abnormal parameter lengths
  • Track privilege changes and password resets in GLPI history logs, and alert on modifications not initiated by the account owner or an administrator
  • Baseline typical AJAX request patterns per user role and alert on deviations, such as low-privilege users triggering high-volume AJAX activity

How to Mitigate CVE-2024-37148

Immediate Actions Required

  • Upgrade GLPI to version 10.0.16 or later, which contains the vendor fix for the vulnerable AJAX scripts
  • Rotate credentials for all GLPI user accounts, especially administrative accounts, after patching
  • Review audit and history logs for unauthorized account modifications made prior to remediation
  • Restrict network access to the GLPI web interface so that only trusted users and networks can authenticate

Patch Information

The GLPI project released version 10.0.16 to remediate CVE-2024-37148. Administrators should follow the upgrade path documented by the vendor and validate the fix by checking the installed version. Refer to the GLPI security advisory GHSA-p626-hph9-p6fj for the complete list of affected files and remediation notes.

Workarounds

  • If immediate upgrade is not possible, restrict access to the GLPI application to authenticated administrators only using network-level controls
  • Place GLPI behind a WAF configured with SQL injection rules targeting the AJAX endpoints
  • Disable non-essential AJAX features in the GLPI configuration until the upgrade is applied
bash
# Configuration example: verify the installed GLPI version and upgrade
cd /var/www/glpi
grep -R "GLPI_VERSION" inc/define.php

# Download and apply the fixed release
wget https://github.com/glpi-project/glpi/releases/download/10.0.16/glpi-10.0.16.tgz
tar -xzf glpi-10.0.16.tgz -C /var/www/

# Run the GLPI upgrade routine via CLI
php bin/console db:update --allow-unstable

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.