CVE Database
/

CVE-2025-23024

Back to search

CVE-2025-23024

Published: Feb 25, 2025

Modified: Feb 25, 2025

PUBLISHED

Description

GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anonymous user can disable all the active plugins. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` file.

VendorProductVersions

glpi-project

glpi

affected
>= 0.72, < 10.0.18

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now