CVE-2025-53112: GLPI's incomprehensive permission checks can lead to data removal from allowed users
Published Jul 30, 2025
·Updated
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal of some specific resources. This is fixed in version 10.0.19.
Affected Software
2 affected components
GLPI GLPI>=9.1.0<=10.0.18
GLPI-PROJECT GLPI>=9.1.0<10.0.19
Event History
Jul 30, 2025
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53112?
CVE-2025-53112 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2025-53112?
To fix CVE-2025-53112, upgrade your GLPI installation to version 10.0.19 or later.
3
What systems are affected by CVE-2025-53112?
CVE-2025-53112 affects GLPI versions between 9.1.0 and 10.0.18.
4
What type of vulnerability is CVE-2025-53112?
CVE-2025-53112 is a permission check vulnerability that allows unauthorized removal of specific resources.
5
What should I do if I cannot upgrade to fix CVE-2025-53112 immediately?
If unable to upgrade immediately, review and restrict user permissions to mitigate the risk of CVE-2025-53112.