CVE 3.5 LOW

GLPI has overly permissive URL verification_CVE-2025-52567

3.5 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided since GLPI 10.0.4 were not robust enough for certain specific cases. This is fixed in version 10.0.19.

Basic Information

ID CVE-2025-52567
Source GitHub_M
Published Jul 30, 2025 at 14:07
Modified Jul 30, 2025 at 19:27

Affected Product

Vendor glpi-project
Product glpi
Version >= 0.84, < 10.0.19
Affected Versions glpi-project glpi >= 0.84, < 10.0.19

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.