PT-2025-6972 · Glpi+2 · Glpi+2

Jcervantes-Sipecom

·

Published

2025-02-12

·

Updated

2025-08-13

·

CVE-2025-23024

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GLPI versions 0.72 through 10.0.17
Description The issue allows an anonymous user to disable all active plugins. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the install/update.php file.
Recommendations For versions 0.72 through 10.0.17, update to version 10.0.18 to resolve the issue. As a temporary workaround, consider deleting the install/update.php file until the patch is applied.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-4115
BDU:2025-04042
CVE-2025-23024
GHSA-885X-HVP2-85Q8

Affected Products

Alt Linux
Glpi
Red Os