CVE-2025-53111: GLPI exposes data to non-allowed users
Published Jul 30, 2025
·Updated
GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.
Affected Software
2 affected components
GLPI GLPI>=0.80<=10.0.18
GLPI-PROJECT GLPI>=0.80<10.0.19
Event History
Jul 30, 2025
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53111?
CVE-2025-53111 has been rated as a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2025-53111?
To fix CVE-2025-53111, update GLPI to version 10.0.19 or later.
3
What versions of GLPI are affected by CVE-2025-53111?
CVE-2025-53111 affects GLPI versions from 0.80 up to 10.0.18.
4
What type of attack can CVE-2025-53111 facilitate?
CVE-2025-53111 can facilitate unauthorized access to restricted resources within GLPI.
5
Is there a patch available for CVE-2025-53111?
Yes, a patch for CVE-2025-53111 is included in GLPI version 10.0.19.