Vulnerability CVE-2025-25192: Information

Description

GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.

Published: Feb. 25, 2025
Modified: March 18, 2025

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.18-alt110.0.18-alt1ALT-PU-2025-4052-1377585Fixed
glpisisyphus_e2k10.0.18-alt110.0.18-alt1ALT-PU-2025-4342-1-Fixed
glpisisyphus_riscv6410.0.18-alt110.0.18-alt1ALT-PU-2025-4139-1-Fixed
glpisisyphus_loongarch6410.0.18-alt110.0.18-alt1ALT-PU-2025-4148-1-Fixed
glpip1110.0.18-alt110.0.18-alt1ALT-PU-2025-4115-2377682Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      End excluding
      10.0.18