CVE-2025-64516: GLPI incorrectly authorizes access to documents
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed in 10.0.21 and 11.0.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64516?
CVE-2025-64516 has a medium severity rating due to the unauthorized access it allows to sensitive documents in GLPI.
How do I fix CVE-2025-64516?
To fix CVE-2025-64516, upgrade GLPI to version 10.0.21 or 11.0.3 or later.
What versions of GLPI are affected by CVE-2025-64516?
CVE-2025-64516 affects GLPI versions prior to 10.0.21 and 11.0.3.
What kind of data is exposed due to CVE-2025-64516?
CVE-2025-64516 allows unauthorized users to access documents attached to tickets, assets, and other items in GLPI.
Is CVE-2025-64516 a critical vulnerability?
CVE-2025-64516 is considered a medium severity vulnerability rather than a critical one.