PT-2025-31384 · Glpi+2 · Glpi+2

Geraldino2

·

Published

2025-07-29

·

Updated

2025-08-27

·

CVE-2025-52567

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 0.84 through 10.0.18
Description GLPI is an Asset and IT Management Software package. Versions 0.84 through 10.0.18 are susceptible to a Server-Side Request Forgery (SSRF) exploit when using RSS feeds or external calendars for planning purposes. Previous security patches implemented since GLPI 10.0.4 were insufficient in certain scenarios.
Recommendations Update to version 10.0.19 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-9984
BDU:2025-10946
CVE-2025-52567
GHSA-5MP6-MGMH-VRQ7

Affected Products

Alt Linux
Glpi
Red Os