6.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Description
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability or misconfiguration), user-controlled data is stored insecurely in the database via computergroup, and is later unserialized on every page load, allowing arbitrary PHP object instantiation. Version 1.1.2 fixes the issue.
Basic Information
ID
CVE-2025-65035
Source
GitHub_M
Published
Dec 19, 2025 at 16:35
Affected Product
Vendor
pluginsGLPI
Product
databaseinventory
Version
< 1.1.2
Affected Versions
pluginsGLPI databaseinventory < 1.1.2