Vulnerability Description
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration rights can change the rules execution order. This issue has been patched in version 10.0.19.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/glpi-project/glpi/releases/tag/10.0.19
- https://github.com/glpi-project/glpi/security/advisories/GHSA-334r-2682-95wc
FAQ
What is CVE-2025-53105?
CVE-2025-53105 is a vulnerability with a CVSS score of 7.5 (HIGH). GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. I...
How severe is CVE-2025-53105?
CVE-2025-53105 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-53105?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.