CVE-2025-53360: pluginsGLPI's Database Inventory Plugin allows any authenticated user to send agent requests
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior to 1.0.3, any authenticated user could send requests to agents. This issue has been patched in version 1.0.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53360?
CVE-2025-53360 is considered a high severity vulnerability due to its impact on inventory agent management.
How do I fix CVE-2025-53360?
To fix CVE-2025-53360, upgrade to the Database Inventory Plugin version 1.0.3 or later.
Who is affected by CVE-2025-53360?
Any user with authenticated access to versions of the Database Inventory Plugin prior to 1.0.3 is affected by CVE-2025-53360.
What type of vulnerability is CVE-2025-53360?
CVE-2025-53360 is an authenticated user privilege escalation vulnerability.
When was CVE-2025-53360 disclosed?
CVE-2025-53360 was disclosed prior to the release of version 1.0.3 of the Database Inventory Plugin.