CVE-2025-25192: GLPI allows unauthorized access to debug mode
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the install/update.php file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.18 - Remove
Remove
install/update.phpfrom your environment.Delete the install/update.php file as a workaround.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25192?
CVE-2025-25192 has a low severity rating as it involves a low privileged user gaining unauthorized access to sensitive information.
How do I fix CVE-2025-25192?
To fix CVE-2025-25192, upgrade GLPI to version 10.0.18 or later.
What is the impact of CVE-2025-25192?
The impact of CVE-2025-25192 allows a low privileged user to enable debug mode and access sensitive information.
Is there a workaround for CVE-2025-25192?
Yes, as a workaround for CVE-2025-25192, you can delete the 'install/update.php' file.
What versions are affected by CVE-2025-25192?
CVE-2025-25192 affects all versions of GLPI prior to 10.0.18.