PT-2025-31227 · Glpi · Glpi

Cedric-Anne

·

Published

2025-07-29

·

Updated

2025-07-29

·

CVE-2025-27514

CVSS v3.1
4.5
VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

GLPI versions 9.5.0 through 10.0.18

Description:

GLPI is an Asset and IT Management Software package. A technician can utilize a malicious payload to trigger a stored Cross-Site Scripting (XSS) issue on the project's kanban.

Recommendations:

Update to version 10.0.19 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-27514
GHSA-JH8J-GQXC-6GQJ

Affected Products

Glpi