GLPI Planning Feature Phishing Vulnerability

Vulnerability

A vulnerability allowing phishing attacks has been identified in GLPI versions 9.1.0 prior to 10.0.18. The issue arises from the planning feature, where an unauthenticated user can send a malicious link to attempt a phishing attack.

Impact

This vulnerability could be exploited to conduct phishing attacks, potentially leading to unauthorized access or information disclosure.

Remediation

Users are advised to upgrade to GLPI version 10.0.19.

Added: Jul 30, 2025, 2:30 PM
Updated: Jul 30, 2025, 2:30 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.