CVE-2025-53113

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links feature to fetch information on items they do not have the right to see. This is fixed in version 10.0.19.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

History

04 Aug 2025, 18:57

Type Values Removed Values Added
References () https://github.com/glpi-project/glpi/security/advisories/GHSA-r2mm-6499-4m8j - () https://github.com/glpi-project/glpi/security/advisories/GHSA-r2mm-6499-4m8j - Vendor Advisory
First Time Glpi-project
Glpi-project glpi
CPE cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

30 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-30 15:15

Updated : 2025-08-04 18:57


NVD link : CVE-2025-53113

Mitre link : CVE-2025-53113


JSON object : View

Products Affected

glpi-project

  • glpi
CWE
CWE-862

Missing Authorization

CWE-284

Improper Access Control