Improper Access Control in Escalade Plugin for GLPI
CVE-2025-27153

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 July 2025

What is CVE-2025-27153?

The Escalade GLPI plugin, designed to assist in ticket escalation processes, suffers from an improper access control vulnerability prior to version 2.9.11. This vulnerability can allow unauthorized access, leading to potential data exposure and disruptions in the workflow. Users are strongly advised to update to version 2.9.11 or later to mitigate this risk and ensure secure operations.

Affected Version(s)

escalade < 2.9.11

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-27153 : Improper Access Control in Escalade Plugin for GLPI