GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.
References
Configurations
History
19 Feb 2026, 16:20
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Glpi-project
Glpi-project glpi |
|
| CPE | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| References | () https://github.com/glpi-project/glpi/commit/a3d5cc4a63ae592c0b5592ebe6d562164904dab3 - Patch | |
| References | () https://github.com/glpi-project/glpi/security/advisories/GHSA-62p9-prpq-j62q - Vendor Advisory |
16 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-16 22:15
Updated : 2026-02-19 16:20
NVD link : CVE-2025-64520
Mitre link : CVE-2025-64520
CVE.ORG link : CVE-2025-64520
JSON object : View
Products Affected
glpi-project
- glpi
CWE
CWE-862
Missing Authorization
