7.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Description
The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2.
Basic Information
ID
CVE-2025-54780
Source
GitHub_M
Published
Aug 5, 2025 at 00:08
Modified
Aug 5, 2025 at 14:14
Affected Product
Vendor
cconard96
Product
glpi-screenshot-plugin
Version
< 2.0.2
Affected Versions
cconard96 glpi-screenshot-plugin < 2.0.2