7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed in 10.0.21 and 11.0.3.
Basic Information
ID
CVE-2025-64516
Source
GitHub_M
Published
Jan 15, 2026 at 16:01
Modified
Jan 15, 2026 at 16:08
Affected Product
Vendor
glpi-project
Product
glpi
Version
>= 10.0.0, < 10.0.21
Affected Versions
glpi-project glpi >= 10.0.0, < 10.0.21
glpi-project glpi >= 11.0.0, < 11.0.3
glpi-project glpi >= 11.0.0, < 11.0.3
CWE Classification
References
- github.com /glpi-project/glpi/security/advisories/GHSA-487h-7mxm-7r46
- github.com /glpi-project/glpi/commit/51412a89d3174cfe22967b051d527febdbceab3c
- github.com /glpi-project/glpi/commit/ee7ee28e0645198311c0a9e0c4e4b712b8788e27
- github.com /glpi-project/glpi/releases/tag/10.0.21
- github.com /glpi-project/glpi/releases/tag/11.0.3