Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N >= 9.1.0, < 10.0.21
affected
Description
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.
Problem types
CWE-862: Missing Authorization
Product status
References
github.com/...t/glpi/security/advisories/GHSA-62p9-prpq-j62q
github.com/...ommit/a3d5cc4a63ae592c0b5592ebe6d562164904dab3
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.