CVE-2025-65035
Last modified
CVE-2025-65035 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability or misconfiguration), user-controlled data is stored insecurely in the database via computergroup, and is later unserialized on every page load, allowing arbitrary PHP object instantiation. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability or misconfiguration), user-controlled data is stored insecurely in the database via computergroup, and is later unserialized on every page load, allowing arbitrary PHP object instantiation. Version 1.1.2 fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-65035?
How severe is CVE-2025-65035?
How do I fix CVE-2025-65035?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6503A vulnerability was found in code-projects Inventory Managem…9.8
- CVE-2025-65030Rallly is an open-source scheduling and collaboration tool. …7.1
- CVE-2025-65031Rallly is an open-source scheduling and collaboration tool. …6.5
- CVE-2025-65032Rallly is an open-source scheduling and collaboration tool. …6.5
- CVE-2025-65033Rallly is an open-source scheduling and collaboration tool. …8.1
- CVE-2025-65034Rallly is an open-source scheduling and collaboration tool. …8.1
- CVE-2025-65036XWiki Remote Macros provides XWiki rendering macros that are…8.3
- CVE-2025-65037Improper control of generation of code ('code injection') in…10
- CVE-2025-6504In HDP Server versions below 4.6.2.2978 on Linux, unauthoriz…8.4
- CVE-2025-65041Improper authorization in Microsoft Partner Center allows an…9.8
- CVE-2025-65046Microsoft Edge (Chromium-based) Spoofing Vulnerability3.1
- CVE-2025-6505Unauthorized access and impersonation can occur in versions …8.1
Are you affected by CVE-2025-65035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
