In GLPI (a free asset and IT management software), versions 11.0.0 up to but not including 11.0.3 contain an SQL injection vulnerability reachable by an unauthenticated user via the inventory endpoint. A remote attacker can supply crafted input to the inventory endpoint that is incorporated into backend SQL queries without sufficient sanitization/parameterization, enabling SQL injection. The issue is fixed in GLPI 11.0.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small proof-of-concept exploit for CVE-2025-66417 affecting GLPI 11.0.0 through < 11.0.3. The main entry point is `cve-2025-66417.py`, a Python script that performs an unauthenticated HTTP POST to a user-supplied GLPI inventory endpoint (typically `/front/inventory.php`) with `Content-Type: text/xml`. The XML body injects SQL via the `<deviceid>` field using a CDATA section: `' AND EXTRACTVALUE(1, CONCAT(0x7e, IFNULL((SELECT DATABASE()), 'NONE'), 0x7e))-- -`, aiming to leak the current database name (surrounded by `~`) through an error-based/blind SQLi technique. The script prints the HTTP status code and full response body, but does not implement automated extraction loops, timing-based inference, authentication bypass, or post-exploitation actions. A standalone `cve-2025-66417.xml` file mirrors the same payload for manual testing, and `README.md` documents affected versions and basic usage.
Repository contains only two Markdown files (README.md and poc.md) that both document the same raw HTTP proof-of-concept request for CVE-2025-66417. The PoC targets a web application endpoint POST /front/inventory.php with Content-Type: text/xml and supplies an XML body where <deviceid> is wrapped in CDATA and contains an error-based SQL injection payload using MySQL/MariaDB EXTRACTVALUE() to provoke an error that should echo concatenated data. The intended leaked value is the current database name (likely meant to be SELECT DATABASE(), but the PoC text shows a probable typo: DATBASE()). No automation, shell payload, or post-exploitation is included—this is a manual request template demonstrating the injection vector and expected information disclosure via the HTTP response.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.