Skip to main content
Vulnerability Database/CVE-2025-25192

CVE-2025-25192: GLPI Information Disclosure Vulnerability

CVE-2025-25192 is an information disclosure vulnerability in GLPI asset management software allowing low privileged users to enable debug mode and access sensitive data. This article covers technical details, affected versions, security impact, and mitigation strategies.

Updated:

CVE-2025-25192 Overview

GLPI is a free asset and IT management software package used by organizations to track infrastructure, licenses, tickets, and inventory. CVE-2025-25192 affects GLPI versions prior to 10.0.18. A low-privileged authenticated user can enable debug mode through the install/update.php endpoint and access sensitive information exposed by the application. The issue is classified as an information exposure weakness [CWE-200]. Version 10.0.18 contains the official patch. Administrators unable to upgrade can remove the install/update.php file as a temporary workaround.

Critical Impact

Authenticated low-privileged users can toggle debug mode in GLPI and read sensitive runtime data, including SQL queries, session details, and internal configuration values.

Affected Products

  • GLPI versions prior to 10.0.18
  • glpi-project/glpi source distributions
  • Self-hosted GLPI deployments exposing install/update.php

Discovery Timeline

  • 2025-02-25 - CVE-2025-25192 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in the NVD database

Technical Details for CVE-2025-25192

Vulnerability Analysis

The flaw is an information disclosure issue in GLPI's installation and update workflow. The install/update.php script remains reachable after installation and does not enforce administrative privileges before allowing debug mode to be toggled. Once debug mode is active, GLPI surfaces internal diagnostic data such as executed SQL statements, PHP errors, session variables, and configuration parameters. Any authenticated user, including accounts with the lowest role, can trigger this state and read the disclosed information from subsequent pages.

The disclosed data can accelerate follow-on attacks. SQL query traces reveal table structures and parameter handling, aiding injection attempts. Session and configuration details assist in privilege escalation or lateral movement inside the GLPI instance. The vulnerability affects confidentiality but does not directly modify data or affect availability.

Root Cause

The root cause is a missing access control check on the install/update.php script. The file is intended for administrators performing upgrades but is left available to any authenticated session. This design flaw maps to [CWE-200] Exposure of Sensitive Information to an Unauthorized Actor.

Attack Vector

Exploitation requires network access to the GLPI web interface and valid credentials for any account, including the default self-service role. The attacker requests the update script to enable debug mode, then navigates the application to harvest the diagnostic output. No user interaction from an administrator is required.

No public proof-of-concept exploit code is currently listed for this issue. Refer to the GitHub Security Advisory GHSA-86cx-hcfc-8mm8 for the vendor's technical description.

Detection Methods for CVE-2025-25192

Indicators of Compromise

  • HTTP requests from non-administrative sessions to install/update.php on the GLPI web server.
  • Application logs showing debug or verbose output being served to standard user roles.
  • Unexpected changes to the GLPI configuration flag that governs debug mode.

Detection Strategies

  • Inspect web server access logs for GET or POST requests to /install/update.php outside of planned maintenance windows.
  • Correlate authenticated session identifiers with requests to installation scripts to flag low-privilege accounts touching administrative endpoints.
  • Alert on GLPI pages returning SQL traces, PHP stack traces, or debug toolbars to sessions that lack administrative rights.

Monitoring Recommendations

  • Enable and centralize GLPI application logs, then forward them to a SIEM for query-based detection of debug activity.
  • Monitor the glpi_configs table or equivalent configuration store for changes to debug settings.
  • Review the Vicarius detection post for CVE-2025-25192 for additional query examples.

How to Mitigate CVE-2025-25192

Immediate Actions Required

  • Upgrade GLPI to version 10.0.18 or later, published in the GLPI 10.0.18 release notes.
  • Delete or restrict access to the install/update.php file on all production GLPI servers.
  • Audit existing user accounts and disable those that are not required, reducing the pool of accounts that could abuse this flaw.

Patch Information

The GLPI project released version 10.0.18 with a fix that removes the ability for low-privileged users to enable debug mode. Details are provided in the GitHub Security Advisory GHSA-86cx-hcfc-8mm8 and the 10.0.18 release notes.

Workarounds

  • Delete the install/update.php file from the GLPI web root once installation or upgrade tasks are complete.
  • Place the install/ directory behind a web server access control rule that limits requests to administrator IP ranges.
  • Follow the Vicarius mitigation guide for CVE-2025-25192 for step-by-step hardening instructions.
bash
# Remove the vulnerable installer script from the GLPI web root
rm /var/www/html/glpi/install/update.php

# Or block the endpoint at the web server (Nginx example)
# location = /install/update.php { deny all; return 403; }

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.