VYPR
Low severity3.5NVD Advisory· Published Jul 30, 2025· Updated Jun 17, 2026

CVE-2025-52567

CVE-2025-52567

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided since GLPI 10.0.4 were not robust enough for certain specific cases. This is fixed in version 10.0.19.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Glpi Project/Glpi3 versions
    cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: >=0.84,<10.0.19
    • (no CPE)range: 10.0.4 <= 10.0.18
    • (no CPE)range: >= 0.84, < 10.0.19

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.