GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- 10.0.17
A vulnerability exists in GLPI versions prior to 10.0.18, allowing low-privileged users to enable debug mode and access sensitive information. This issue arises because the 'install/update.php' file remains accessible after installation, creating a potential security risk. Exploiting this vulnerability can lead to unauthorized access and system compromise.
Enabling debug mode can expose sensitive information, potentially leading to unauthorized actions or system compromise.
To reproduce this vulnerability, verify if the GLPI installation is on a version prior to 10.0.18. Check for the presence of the 'install/update.php' file, which should not be accessible after installation. If this file is found, the system is vulnerable to CVE-2025-25192.
Users can upgrade to GLPI version 10.0.18, which addresses this vulnerability. Alternatively, the 'install/update.php' file can be deleted to mitigate the issue.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.