CVE-2025-64516

HIGH EPSS 19.4%
Published Jan 15, 20265mo ago · Modified Jun 17, 20261w ago
7.5 CVSS 3.1
High
Find Similar
Published Jan 15, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago

Description

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed in 10.0.21 and 11.0.3.

CVSS Details

Base Score
7.5
Exploitability
3.9
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
19.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 2

CWE-284
CWE-639

Affected Products 2

VendorProductVersionRange
glpi-projectglpi*≥10.0.0  –  <10.0.21
glpi-projectglpi*≥11.0.0  –  <11.0.3

References 5

  • github.com https://github.com/glpi-project/glpi/commit/51412a89d3174cfe22967b051d527febdbceab3c
    Patch
  • github.com https://github.com/glpi-project/glpi/commit/ee7ee28e0645198311c0a9e0c4e4b712b8788e27
    Patch
  • github.com https://github.com/glpi-project/glpi/releases/tag/10.0.21
    Release Notes
  • github.com https://github.com/glpi-project/glpi/releases/tag/11.0.3
    Release Notes
  • github.com https://github.com/glpi-project/glpi/security/advisories/GHSA-487h-7mxm-7r46
    Vendor Advisory

Remediation

  • github.com https://github.com/glpi-project/glpi/commit/51412a89d3174cfe22967b051d527febdbceab3c
    Patch
  • github.com https://github.com/glpi-project/glpi/commit/ee7ee28e0645198311c0a9e0c4e4b712b8788e27
    Patch