CVE-2025-27147

The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-25 15:15

Updated : 2025-03-25 15:15


NVD link : CVE-2025-27147

Mitre link : CVE-2025-27147


JSON object : View

Products Affected

No product.

CWE
CWE-552

Files or Directories Accessible to External Parties

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path