Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23571 | The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2. |
Tue, 05 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cconard96
Cconard96 glpi Screenshot Plugin |
|
| Vendors & Products |
Cconard96
Cconard96 glpi Screenshot Plugin |
Tue, 05 Aug 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2. | |
| Title | glpi-screenshot-plugin exposes local files in /ajax/screenshot.php | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-05T14:14:53.642Z
Reserved: 2025-07-29T16:50:28.391Z
Link: CVE-2025-54780
Updated: 2025-08-05T14:14:50.325Z
Status : Deferred
Published: 2025-08-05T01:15:41.717
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54780
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:38:48Z
EUVD