#VU104186 Information disclosure in GLPI - CVE-2025-21626

 

#VU104186 Information disclosure in GLPI - CVE-2025-21626

Published: February 25, 2025


Vulnerability identifier: #VU104186
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-21626
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
GLPI
Software vendor:
glpi-project

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the setup.php file. A remote attacker can gain unauthorized access to sensitive information on the system, related to LDAP directories, mail servers authentication providers and mail receivers.


Remediation

Install updates from vendor's website.

External links