CVE-2025-64520

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

History

19 Feb 2026, 16:20

Type Values Removed Values Added
First Time Glpi-project
Glpi-project glpi
CPE cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
References () https://github.com/glpi-project/glpi/commit/a3d5cc4a63ae592c0b5592ebe6d562164904dab3 - () https://github.com/glpi-project/glpi/commit/a3d5cc4a63ae592c0b5592ebe6d562164904dab3 - Patch
References () https://github.com/glpi-project/glpi/security/advisories/GHSA-62p9-prpq-j62q - () https://github.com/glpi-project/glpi/security/advisories/GHSA-62p9-prpq-j62q - Vendor Advisory

16 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 22:15

Updated : 2026-02-19 16:20


NVD link : CVE-2025-64520

Mitre link : CVE-2025-64520

CVE.ORG link : CVE-2025-64520


JSON object : View

Products Affected

glpi-project

  • glpi
CWE
CWE-862

Missing Authorization