CVE-2025-25192
CVE-2025-25192
Título es
CVE-2025-25192
Mar, 25/02/2025 – 18:15
Tipo
CWE-200
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-25192
Descripción en
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.
25/02/2025
25/02/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
6.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://github.com/glpi-project/glpi/releases/tag/10.0.18
https://github.com/glpi-project/glpi/security/advisories/GHSA-86cx-hcfc-8mm8
Enviar en el boletín
Off
