Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23163 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided since GLPI 10.0.4 were not robust enough for certain specific cases. This is fixed in version 10.0.19. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 04 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* |
Thu, 31 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| Vendors & Products |
Glpi-project
Glpi-project glpi |
Wed, 30 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 0.84 through 10.0.18, usage of RSS feeds or external calendars when planning is subject to SSRF exploit. The previous security patches provided since GLPI 10.0.4 were not robust enough for certain specific cases. This is fixed in version 10.0.19. | |
| Title | GLPI has overly permissive URL verification | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-30T19:27:34.141Z
Reserved: 2025-06-18T03:55:52.036Z
Link: CVE-2025-52567
Updated: 2025-07-30T19:27:29.118Z
Status : Analyzed
Published: 2025-07-30T14:15:28.193
Modified: 2025-08-04T18:54:47.740
Link: CVE-2025-52567
No data.
OpenCVE Enrichment
Updated: 2025-07-31T09:15:40Z
EUVD