PT-2025-31388 · Glpi+2 · Glpi+2

Cconard96

·

Published

2025-07-29

·

Updated

2025-10-07

·

CVE-2025-53112

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 9.1.0 through 10.0.18
Description GLPI is an Asset and IT Management Software package providing ITIL Service Desk features, licenses tracking, and software auditing. A lack of permission checks in affected versions can result in unauthorized removal of specific resources.
Recommendations Update to version 10.0.19 or later.

Exploit

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-9984
BDU:2025-12946
CVE-2025-53112
GHSA-RP7W-6343-3M2R

Affected Products

Alt Linux
Glpi
Red Os