GLPI’s incomprehensive permission checks can lead to data removal from allowed users

CVE Details

Basic Information

Title GLPI’s incomprehensive permission checks can lead to data removal from allowed users
Type cve
Published 2025-07-30T14:15:22.000Z
Modified 2025-07-30T14:15:22.000Z

Product Information

Vendor glpi-project
Product glpi
Version >= 9.1.0, < 10.0.19

CVSS Information

Base Score 4.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected Products

  • glpi-project glpi >= 9.1.0, < 10.0.19

Additional Information

CWE List CWE-284, CWE-862
Source GitHub_M

Description

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal of some specific resources. This is fixed in version 10.0.19.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.