CVE-2025-52897: GLPI is vulnerable to XSS and open redirection attacks through planning feature
Published Jul 30, 2025
·Updated
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.
Affected Software
2 affected components
GLPI GLPI>=9.1.0<=10.0.18
GLPI-PROJECT GLPI>=9.1.0<10.0.19
Event History
Jul 30, 2025
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52897?
CVE-2025-52897 is classified as a high severity vulnerability due to the potential for phishing attacks by unauthenticated users.
2
How do I fix CVE-2025-52897?
To fix CVE-2025-52897, upgrade GLPI to version 10.0.19 or later.
3
Who is affected by CVE-2025-52897?
Any user of GLPI versions 9.1.0 through 10.0.18 is affected by CVE-2025-52897.
4
What kind of attack is possible with CVE-2025-52897?
CVE-2025-52897 allows an unauthenticated user to send a malicious link for phishing attacks using the planning feature.
5
Is there a workaround for CVE-2025-52897?
There are no known effective workarounds for CVE-2025-52897; the only solution is to upgrade to the patched version.