TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-53113

LOW
2.7

Description

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links feature to fetch information on items they do not have the right to see. This is fixed in version 10.0.19.

Details CVE

Score CVSS v3.12.7
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie7/30/2025
Derniere modification8/4/2025
Sourcenvd
Observations honeypot0

Produits affectes

glpi-project:glpi

Faiblesses (CWE)

CWE-284CWE-862

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.