PT-2026-25776 · Glpi · Fields Plugin

Login-Securite

·

Published

2026-03-16

·

Updated

2026-03-17

·

CVE-2026-23489

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI Fields plugin versions prior to 1.23.3
Description The Fields plugin for GLPI allows users to add custom fields to GLPI item forms. Prior to version 1.23.3, users permitted to create dropdowns could execute arbitrary PHP code. This allows for the potential execution of malicious code through the creation of specially crafted dropdowns. The vulnerable component is the functionality related to creating dropdowns within the plugin. The createDropdowns() function is implicated in this issue. The vulnerable parameter is the input provided during dropdown creation.
Recommendations Versions prior to 1.23.3 should be updated to version 1.23.3 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-23489
GHSA-RJ7Q-MMX9-FHQ7

Affected Products

Fields Plugin