PT-2026-3058 · Glpi+1 · Glpi+1
Published
2026-01-15
·
Updated
2026-03-19
·
CVE-2025-64516
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GLPI versions prior to 10.0.21
GLPI versions prior to 11.0.3
Description
An unauthorized user can access GLPI documents attached to any item, such as tickets or assets. If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user.
Recommendations
Update to version 10.0.21 or later.
Update to version 11.0.3 or later.
Exploit
Fix
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Glpi
Red Os