GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Mar 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Glpi-project
Glpi-project glpi |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
Vendors & Products |
Glpi-project
Glpi-project glpi |
|
References |
|
Tue, 25 Feb 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file. | |
Title | GLPI allows unauthorized access to debug mode | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-02-25T17:58:20.388Z
Updated: 2025-03-18T17:03:35.247Z
Reserved: 2025-02-03T19:30:53.400Z
Link: CVE-2025-25192

Updated: 2025-03-18T17:03:35.247Z

Status : Modified
Published: 2025-02-25T18:15:27.583
Modified: 2025-03-18T17:15:45.720
Link: CVE-2025-25192

No data.