CVE-2025-27147HIGH 8.2EPSS p29.7%
CVE-2025-27147CVE-2025-27147
Description
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.
Scoring
| CVSS 3.1 | 8.2 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L |
| EPSS | 0.38% probability of exploitation · percentile 29.7% · 2026-06-19T12:03:05Z |
| Published | 2025-03-25 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-22 | 0% | live |
| Weakness | Files or Directories Accessible to External Partiescwe-552 | 0% | live |
| Weakness | External Control of File Name or Pathcwe-73 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.