GLPI Reservation Modification Vulnerability Allowing Unauthorized User Interference

Vulnerability

A vulnerability exists in GLPI versions 0.78 through 10.0.18, allowing connected users to modify the reservations of other users. This issue has been addressed in version 10.0.19.

Impact

Exploitation of this vulnerability allows a user to change another user's reservations, potentially leading to unauthorized access or changes in resource allocation.

Remediation

Users are advised to upgrade to GLPI version 10.0.19.

Added: Jul 30, 2025, 3:24 PM
Updated: Jul 30, 2025, 3:24 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.