Skip to main content
Vulnerability Database/CVE-2025-53008

CVE-2025-53008: GLPI Information Disclosure Vulnerability

CVE-2025-53008 is an information disclosure vulnerability in GLPI Asset Management Software that allows authenticated users to steal mail receiver credentials through malicious payloads. This article covers technical details, affected versions from 9.3.1 to 10.0.19, security impact, and available patches.

Published:

CVE-2025-53008 Overview

CVE-2025-53008 is a credential exposure vulnerability in GLPI (Gestionnaire Libre de Parc Informatique), an open-source IT asset and service management platform. The flaw affects versions 9.3.1 through 10.0.18 and allows an authenticated user to craft a malicious payload that exfiltrates stored mail receiver credentials. GLPI project maintainers addressed the issue in version 10.0.19. The weakness is classified under CWE-522: Insufficiently Protected Credentials.

Critical Impact

Any authenticated GLPI user can steal credentials configured for mail receivers, potentially exposing mailbox accounts used for ticket ingestion and enabling downstream compromise of email infrastructure.

Affected Products

  • GLPI versions 9.3.1 through 10.0.18
  • glpi-project/glpi (all editions within the affected range)
  • Deployments using mail receiver (mail collector) integrations

Discovery Timeline

  • 2025-07-30 - CVE-2025-53008 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-53008

Vulnerability Analysis

GLPI supports mail receivers (mail collectors) that connect to remote IMAP or POP mailboxes to ingest email as tickets. The credentials for those mailboxes are stored server-side and rendered back into administrative forms during editing. In affected versions, an authenticated user can supply a malicious payload that causes the application to disclose the stored mail receiver credentials to the attacker.

Because exploitation only requires an authenticated session and no user interaction from an administrator, any low-privileged account with access to the relevant interfaces can trigger disclosure. The stolen credentials frequently correspond to shared service mailboxes with broad access, which extends the impact beyond GLPI itself.

Root Cause

The root cause is insufficient protection of stored credentials [CWE-522]. Mail receiver passwords are handled in a way that allows retrieval through a crafted request rather than being restricted to server-side use for authentication against the mail server. The GLPI security advisory GHSA-52h8-76ph-4j9q documents the fix.

Attack Vector

The attack is network-based and requires an existing authenticated session on the GLPI instance. An attacker submits a crafted payload targeting the mail receiver configuration workflow and receives the plaintext credentials in the response. No administrative privileges and no victim interaction are required.

No public proof-of-concept exploit is currently listed for CVE-2025-53008, and the vulnerability is not present on the CISA Known Exploited Vulnerabilities list. Technical exploitation details are described in the vendor advisory referenced above.

Detection Methods for CVE-2025-53008

Indicators of Compromise

  • Unexpected read or edit requests against mail receiver (MailCollector) endpoints from non-administrative user accounts.
  • Outbound authentication attempts to configured IMAP or POP mail servers originating from hosts other than the GLPI application server.
  • Password reset events on mailbox accounts used by GLPI mail receivers that were not initiated by administrators.

Detection Strategies

  • Review GLPI application and web server access logs for requests to mail collector configuration URLs made by users outside the administrator role.
  • Correlate GLPI session activity with mail server authentication logs to identify credential reuse from unexpected source addresses.
  • Alert on anomalous access to the glpi_mailcollectors database table, particularly read operations initiated through the web tier.

Monitoring Recommendations

  • Enable verbose audit logging in GLPI and forward events to a centralized SIEM for correlation with authentication telemetry.
  • Monitor privileged configuration areas of GLPI for read access by low-privileged accounts, which should be rare in normal operation.
  • Track mail server login sources and flag deviations from the expected GLPI application server IP addresses.

How to Mitigate CVE-2025-53008

Immediate Actions Required

  • Upgrade GLPI to version 10.0.19 or later, which contains the vendor fix for CVE-2025-53008.
  • Rotate all mail receiver passwords stored in GLPI, assuming they may have been exposed on unpatched instances.
  • Audit GLPI user accounts and revoke access for stale, unused, or over-privileged users to reduce the pool of potential attackers.

Patch Information

The GLPI project resolved this issue in version 10.0.19. Administrators should apply the upgrade following the standard GLPI upgrade procedure and verify the installed version through the Setup > General interface. Full details are available in GitHub Security Advisory GHSA-52h8-76ph-4j9q.

Workarounds

  • Restrict network access to the GLPI web interface to trusted administrative networks until the patch is applied.
  • Temporarily disable mail receivers or remove stored credentials from GLPI if upgrading immediately is not possible.
  • Use dedicated, least-privilege mailbox accounts for GLPI mail collection so that credential exposure does not grant access to broader mail infrastructure.
bash
# Verify installed GLPI version after upgrade
grep -R "GLPI_VERSION" /var/www/glpi/inc/define.php

# Rotate mail receiver credentials via the GLPI UI:
# Setup > Mail collectors > select collector > update password

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.