← Back to CVEs
CVE-2025-53113
LOW2.7
Description
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links feature to fetch information on items they do not have the right to see. This is fixed in version 10.0.19.
CVE Details
CVSS v3.1 Score2.7
SeverityLOW
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published7/30/2025
Last Modified8/4/2025
Sourcenvd
Honeypot Sightings0
Affected Products
glpi-project:glpi
Weaknesses (CWE)
CWE-284CWE-862
References
https://github.com/glpi-project/glpi/security/advisories/GHSA-r2mm-6499-4m8j(security-advisories@github.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.