CVE-2025-21626 MEDIUM

CVE-2025-21626: GLPI vulnerable to exposure of sensitive information in the `status.php` endpoint

Vendor Glpi-Project
Product glpi
Weakness CWE-200 · Info exposure
Published February 25, 2025
Last update February 25, 2025

CVSS base score

5.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the `status.php` endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the `status.php` file, restrict its access, or remove any sensitive values from the `name` field of the active LDAP directories, mail servers authentication providers and mail receivers.

Key dates

02Disclosure timeline

February 25, 2025 CVE published
February 25, 2025 Record updated

Related vulnerabilities

04Related CVE