CVE-2025-64516

Source
https://cve.org/CVERecord?id=CVE-2025-64516
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64516.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64516
Aliases
  • GHSA-487h-7mxm-7r46
Downstream
Published
2026-01-15T16:01:03.470Z
Modified
2026-08-08T03:47:56.946400682Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
GLPI incorrectly authorizes access to documents
Details

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This vulnerability is fixed in 10.0.21 and 11.0.3.

Database specific
{
    "cwe_ids": [
        "CWE-284",
        "CWE-639"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64516.json"
}
References

Affected packages

Git / github.com/glpi-project/glpi

Affected ranges

Type
GIT
Repo
https://github.com/glpi-project/glpi
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.0.21"
        },
        {
            "introduced": "11.0.0"
        },
        {
            "fixed": "11.0.3"
        }
    ]
}

Affected versions

10.*
10.0.0
10.0.1
10.0.10
10.0.11
10.0.12
10.0.13
10.0.14
10.0.15
10.0.16
10.0.17
10.0.18
10.0.19
10.0.2
10.0.20
10.0.3
10.0.4
10.0.5
10.0.6
10.0.7
10.0.8
10.0.9
11.*
11.0.0
11.0.1
11.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64516.json"