CVE-2025-53113: GLPI technicians can access unauthorized information through external links
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links feature to fetch information on items they do not have the right to see. This is fixed in version 10.0.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53113?
CVE-2025-53113 has been classified as a high severity vulnerability due to its potential impact on the security of GLPI systems.
How do I fix CVE-2025-53113?
To fix CVE-2025-53113, upgrade GLPI to a version later than 10.0.18.
What versions of GLPI are affected by CVE-2025-53113?
CVE-2025-53113 affects GLPI versions from 0.65 to 10.0.18.
What is the nature of the vulnerability in CVE-2025-53113?
CVE-2025-53113 allows a technician to exploit the external links feature, potentially leading to unauthorized access.
Is there a patch available for CVE-2025-53113?
Yes, a patch is available in the form of an upgrade to a version beyond 10.0.18 of GLPI.