CVE-2025-52567: GLPI has overly permissive URL verification
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided since GLPI 10.0.4 were not robust enough for certain specific cases. This is fixed in version 10.0.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52567?
CVE-2025-52567 has a medium to high severity due to the potential for SSRF exploitation.
How do I fix CVE-2025-52567?
To fix CVE-2025-52567, update GLPI to the latest version beyond 10.0.18 where the vulnerability is patched.
What versions of GLPI are affected by CVE-2025-52567?
CVE-2025-52567 affects GLPI versions from 0.84 to 10.0.18.
What is SSRF in the context of CVE-2025-52567?
SSRF, or Server-Side Request Forgery, allows an attacker to make requests from the server to internal or external resources.
Can CVE-2025-52567 be exploited remotely?
Yes, CVE-2025-52567 can be exploited remotely, making it a significant security concern.