Unrated severityNVD Advisory· Published Feb 25, 2025· Updated Feb 25, 2025
GLPI vulnerable to exposure of sensitive information in the `status.php` endpoint
CVE-2025-21626
Description
GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive information from the status.php endpoint. Version 10.0.18 contains a fix for the issue. Some workarounds are available. One may delete the status.php file, restrict its access, or remove any sensitive values from the name field of the active LDAP directories, mail servers authentication providers and mail receivers.
Affected products
1- Range: >= 0.71, < 10.0.18
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/glpi-project/glpi/releases/tag/10.0.18mitrex_refsource_MISC
- github.com/glpi-project/glpi/security/advisories/GHSA-5vvr-pxwf-3w77mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.