Impact
GLPI applications up to version 12.0.0 lack an authorization check in the ajax/map.php endpoint, permitting a low‑privileged user who has authenticated to query item types that the user normally cannot see. By submitting crafted itemtype identifiers such as Contact, Supplier, Contract or Budget together with search parameters, the attacker can receive match counts, titles and spatial coordinates belonging to the user’s entity. This results in disclosure of metadata that should be restricted to higher‑privileged users.
Affected Systems
The flaw affects all GLPI installations running version 12.0.0 or earlier, regardless of deployment environment. Products are available under the glpi-project vendor and are named GLPI.
Risk and Exploitability
The CVSS score is 5.3, indicating medium severity. No EPSS score is available, and the vulnerability is not catalogued as a known exploited vulnerability in CISA's KEV. Exploitation requires only standard authentication and no special conditions; an attacker with any legitimate login can submit the malformed request to the upstream endpoint. Because the flaw is confined to data disclosure and does not grant code execution or privilege elevation, the impact is limited to information leakage. The lack of a public exploitation matrix suggests the attack vector is primarily manual, though automated scripts could enumerate itemtypes.
OpenCVE Enrichment