CVE-2025-23024: GLPI: Plugins are disabled accessing one page
Published Feb 25, 2025
·Updated
GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the install/update.php file.
Affected Software
2 affected components
GLPI GLPI>=0.72<10.0.18
GLPI-PROJECT GLPI>=0.72<10.0.18
Event History
Feb 25, 2025
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23024?
CVE-2025-23024 has been classified as a medium severity vulnerability due to its potential impact on plugin management.
2
How do I fix CVE-2025-23024?
To fix CVE-2025-23024, upgrade to GLPI version 10.0.18 or later.
3
What versions of GLPI are affected by CVE-2025-23024?
CVE-2025-23024 affects GLPI versions from 0.72 up to, but not including, 10.0.18.
4
What is the workaround for CVE-2025-23024?
A temporary workaround for CVE-2025-23024 is to delete the install/update.php file from the GLPI directory.
5
Can an anonymous user exploit CVE-2025-23024?
Yes, an anonymous user can exploit CVE-2025-23024 to disable all active plugins in the affected versions of GLPI.