GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.
References
Configurations
History
No history.
Information
Published : 2025-12-16 22:15
Updated : 2026-02-19 16:20
NVD link : CVE-2025-64520
Mitre link : CVE-2025-64520
CVE.ORG link : CVE-2025-64520
JSON object : View
Products Affected
glpi-project
- glpi
CWE
CWE-862
Missing Authorization
