PT-2025-31227 · Glpi+2 · Glpi+2

Cedric-Anne

·

Published

2025-07-29

·

Updated

2025-08-27

·

CVE-2025-27514

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 9.5.0 through 10.0.18
Description GLPI is an Asset and IT Management Software package. A technician can utilize a malicious payload to trigger a stored Cross-Site Scripting (XSS) issue on the project's kanban.
Recommendations Update to version 10.0.19 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-9984
BDU:2025-10945
CVE-2025-27514
GHSA-JH8J-GQXC-6GQJ

Affected Products

Alt Linux
Glpi
Red Os