GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on which an Oauth authorization has already been established. Version 10.0.18 contains a patch. As a workaround, one may disable any "Mail servers" authentication provider configured to use an Oauth connection provided by the OauthIMAP plugin.
We have discovered 17 live websites that are affected by CVE-2025-23046.
| 2 websites | |
| 3 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 2 websites |
| .com.br | 1 websites |
| .eu | 1 websites |
| .fr | 1 websites |
| .info | 1 websites |
| .it | 1 websites |
| .pl | 1 websites |
| .ru | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.**********.******.***.br | *,***,*** | ||
| ********.*****.it | *,***,*** | ||
| **.********.pl | **,***,*** | ||
| ******.***.***.tr | **,***,*** | ||
| *********************.**.nz | **,***,*** | ||
| ********.****.**********.com | **,***,*** | ||
| *******.*******.fr | **,***,*** | ||
| ********.**********.com | **,***,*** | ||
| ******************.******.***.br | **,***,*** | ||
| *****************.**.nz | **,***,*** |
FAQ