CVE-2025-25192
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 25, 2025
Updated: Feb 28, 2025
CWE ID 200
Summary
CVE-2025-25192: A vulnerability affects GLPI, an open-source IT management software. Before version 10.0.18, a low-privileged user could enable debug mode and gain unauthorized access to sensitive information. To mitigate this issue, update to version 10.0.18 or delete the `install/update.php` file.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- GLPI Project
- Glpi-project GLPI
Affected Vendors
- Teclib
- Glpi-project