CVE-2025-53357: GLPI permits reservation modification by unauthorized users
Published Jul 30, 2025
·Updated
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.78 through 10.0.18, a connected user can alter the reservations of another user. This is fixed in version 10.0.19.
Affected Software
2 affected components
GLPI GLPI>=0.78<=10.0.18
GLPI-PROJECT GLPI>=0.78<10.0.19
Event History
Jul 30, 2025
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53357?
CVE-2025-53357 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-53357?
To fix CVE-2025-53357, update GLPI to version 10.0.19 or later.
3
What versions of GLPI are affected by CVE-2025-53357?
CVE-2025-53357 affects GLPI versions from 0.78 to 10.0.18.
4
What type of vulnerability is CVE-2025-53357?
CVE-2025-53357 is a vulnerability that allows connected users to alter reservations of another user's assets.
5
Who should be concerned about CVE-2025-53357?
Organizations using GLPI versions 0.78 through 10.0.18 should be concerned about CVE-2025-53357 and take action.