CVE-2025-21626

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 25, 2025
Updated: Mar 4, 2025
CWE ID 200

Summary

CVE-2025-21626 is a vulnerability affecting GLPI, a free asset and IT management software. Versions prior to 10.0.18 allow anonymous users to access sensitive information through the `status.php` endpoint. This issue can result in exposure of data, including LDAP directory information and mail server authentication credentials. Users can mitigate the risk by removing sensitive values from affected configurations, restricting access to the `status.php` file, or deleting the file altogether. The vulnerability is resolved in version 10.0.18.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • GLPI Project
  • Glpi-project GLPI

Affected Vendors

  • Teclib
  • Glpi-project