Vulnerability CVE-2025-23024: Information

Description

GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Published: Feb. 25, 2025
Modified: March 4, 2025
Error type identifier: CWE-285

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.18-alt110.0.18-alt1ALT-PU-2025-4052-1377585Fixed
glpisisyphus_e2k10.0.18-alt110.0.18-alt1ALT-PU-2025-4342-1-Fixed
glpisisyphus_riscv6410.0.18-alt110.0.18-alt1ALT-PU-2025-4139-1-Fixed
glpisisyphus_loongarch6410.0.18-alt110.0.18-alt1ALT-PU-2025-4148-1-Fixed
glpip1110.0.18-alt110.0.18-alt1ALT-PU-2025-4115-2377682Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      Start including
      0.72
      End excluding
      10.0.18