CVE-2025-53111 MEDIUM

CVE-2025-53111: GLPI exposes data to non-allowed users

Vendor Glpi-Project
Product glpi
Weakness CWE-284
Published July 30, 2025
Last update July 30, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.

Key dates

02Disclosure timeline

July 30, 2025 CVE published
July 30, 2025 Record updated