PT-2025-6928 · Glpi+2 · Glpi+2

Rootjog

·

Published

2025-02-12

·

Updated

2025-08-13

·

CVE-2025-21626

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 0.71 through 10.0.17
Description The issue allows an anonymous user to fetch sensitive information from the "status.php" endpoint. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions 0.71 through 10.0.17, update to version 10.0.18 to resolve the issue. As a temporary workaround, consider deleting the "status.php" file or restricting its access until a patch is available. Alternatively, remove any sensitive values from the name field of the active LDAP directories, mail servers authentication providers, and mail receivers.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-4115
BDU:2025-04043
CVE-2025-21626
GHSA-5VVR-PXWF-3W77

Affected Products

Alt Linux
Glpi
Red Os