Home

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.

PUBLISHED Reserved 2025-02-26 | Published 2025-07-29 | Updated 2025-07-29 | Assigner GitHub_M




MEDIUM: 4.5CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Problem types

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 9.5.0, < 10.0.19
affected

References

github.com/...t/glpi/security/advisories/GHSA-jh8j-gqxc-6gqj

github.com/...ommit/c340a64a11343bde706d1cd41e4be798dd922303

cve.org (CVE-2025-27514)

nvd.nist.gov (CVE-2025-27514)

Download JSON