CVE-2025-53105: GLPI permits unauthorized rules execution order
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration rights can change the rules execution order. This issue has been patched in version 10.0.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53105?
CVE-2025-53105 is categorized as a medium severity vulnerability.
How do I fix CVE-2025-53105?
To mitigate CVE-2025-53105, upgrade GLPI to version 10.0.19 or later.
What versions of GLPI are affected by CVE-2025-53105?
CVE-2025-53105 affects GLPI versions from 10.0.0 to before 10.0.19.
What type of vulnerability is CVE-2025-53105?
CVE-2025-53105 is an access control vulnerability allowing connected users without admin rights to gain unauthorized access.
Is CVE-2025-53105 present in the latest GLPI release?
No, CVE-2025-53105 is not present in GLPI version 10.0.19 or later.