PT-2025-11260 · Glpi · Glpi Inventory Plugin
Published
2025-03-14
·
Updated
2025-03-14
·
CVE-2025-26626
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GLPI Inventory Plugin versions prior to 1.5.0
Description:
The issue concerns the GLPI Inventory Plugin, which is part of the GLPI asset and IT management software package. It handles various tasks for GLPI agents. The problem is related to reflective cross-site scripting, which could lead to the execution of javascript code.
Recommendations:
For versions prior to 1.5.0, update to version 1.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the plugin to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glpi Inventory Plugin