6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.
Basic Information
ID
CVE-2025-64520
Source
GitHub_M
Published
Dec 16, 2025 at 21:59
Affected Product
Vendor
glpi-project
Product
glpi
Version
>= 9.1.0, < 10.0.21
Affected Versions
glpi-project glpi >= 9.1.0, < 10.0.21