CVE-2025-53008: GLPI's MailCollector Receiver is vulnerable to credential exfiltration
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal mail receiver credentials. This is fixed in version 10.0.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53008?
CVE-2025-53008 is considered a critical vulnerability that allows attackers to steal email information from users.
How do I fix CVE-2025-53008?
To fix CVE-2025-53008, upgrade GLPI to version 10.0.20 or later to mitigate the security risk.
Who is affected by CVE-2025-53008?
CVE-2025-53008 affects users of GLPI versions 9.3.1 through 10.0.19.
What type of attack does CVE-2025-53008 enable?
CVE-2025-53008 enables attackers to use a malicious payload to steal email information from connected users.
When was CVE-2025-53008 disclosed?
CVE-2025-53008 was disclosed in 2025, highlighting a significant security issue within the GLPI software.