PT-2025-51739 · Glpi+2 · Glpi+2

Published

2025-12-16

·

Updated

2026-03-19

·

CVE-2025-59935

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions 10.0.0 through 10.0.20
Description GLPI is an asset and IT management software package. An unauthenticated user can store a cross-site scripting (XSS) payload through the inventory endpoint.
Recommendations Upgrade to version 10.0.21 to receive a patch.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-05704
CVE-2025-59935
GHSA-J8VV-9F8M-R7JX

Affected Products

Alt Linux
Glpi
Red Os