PT-2025-6973 · Unknown+3 · Oauthimap Plugin+3

Moderatetrasher

·

Published

2025-02-12

·

Updated

2025-08-13

·

CVE-2025-23046

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 9.5.0 through 10.0.17
Description The issue allows unauthorized access to GLPI when a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, leveraging existing Oauth authorizations.
Recommendations For versions 9.5.0 through 10.0.17, update to version 10.0.18 to resolve the issue. As a temporary workaround, consider disabling any "Mail servers" authentication provider configured to use an Oauth connection provided by the OauthIMAP plugin.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-4115
BDU:2025-04582
CVE-2025-23046
GHSA-VFXC-QG3V-J2R5

Affected Products

Alt Linux
Glpi
Oauthimap Plugin
Red Os