CVE 6.5 MEDIUM

GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API_CVE-2025-64520

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.

Basic Information

ID CVE-2025-64520
Source GitHub_M
Published Dec 16, 2025 at 21:59

Affected Product

Vendor glpi-project
Product glpi
Version >= 9.1.0, < 10.0.21
Affected Versions glpi-project glpi >= 9.1.0, < 10.0.21

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.