CVE-2025-27153

MEDIUM

Escalade GLPI plugin <2.9.11 - Info Disclosure

Title source: llm
STIX 2.1

Description

Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead to data exposure and workflow disruptions. This issue has been patched in version 2.9.11.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
pluginsGLPI/escalade < 2.9.11
Published Jul 01, 2025
Tracked Since Feb 18, 2026