Security Advisory

CVE-2025-54780

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-05 00:08:37
Last updated 2025-08-05 14:14:53
Assigner GitHub_M
State PUBLISHED

Description

The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2.