Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead to data exposure and workflow disruptions. This issue has been patched in version 2.9.11.
History

Tue, 01 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
Description Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead to data exposure and workflow disruptions. This issue has been patched in version 2.9.11.
Title Escalade GLPI Plugin Vulnerable to Improper Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-01T18:27:50.677Z

Updated: 2025-07-01T19:35:43.790Z

Reserved: 2025-02-19T16:30:47.780Z

Link: CVE-2025-27153

cve-icon Vulnrichment

Updated: 2025-07-01T19:35:07.985Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-01T19:15:25.970

Modified: 2025-07-03T15:14:12.767

Link: CVE-2025-27153

cve-icon Redhat

No data.