CVE-2025-64520: GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64520?
CVE-2025-64520 has a high severity rating as it allows unauthorized users with API access to read all knowledge base entries.
How do I fix CVE-2025-64520?
To fix CVE-2025-64520, users should upgrade to version 10.0.21 of the GLPI software.
What versions of GLPI are affected by CVE-2025-64520?
CVE-2025-64520 affects GLPI versions starting from 9.1.0 and prior to 10.0.21.
Who is at risk from CVE-2025-64520?
Any organization using GLPI versions from 9.1.0 to 10.0.20 is at risk if unauthorized users have API access.
What is GLPI in relation to CVE-2025-64520?
GLPI is an asset and IT management software package that has a vulnerability in versions prior to 10.0.21, identified as CVE-2025-64520.