CVE-2025-25192

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 25, 2025
Updated: Feb 28, 2025
CWE ID 200

Summary

CVE-2025-25192: A vulnerability affects GLPI, an open-source IT management software. Before version 10.0.18, a low-privileged user could enable debug mode and gain unauthorized access to sensitive information. To mitigate this issue, update to version 10.0.18 or delete the `install/update.php` file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • GLPI Project
  • Glpi-project GLPI

Affected Vendors

  • Teclib
  • Glpi-project