PT-2026-45847 · Glp · Glp

·

CVE-2026-5385

·

Published

2026-06-02

·

Updated

2026-06-09

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions glp versions prior to 11.0.7
Description An unauthenticated user with write access to the knowledge base can store a Cross-Site Scripting (XSS) payload in a knowledge base item. XSS is a type of security flaw where malicious scripts are injected into trusted websites.
Recommendations Update to version 11.0.7 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5385
GHSA-2FG5-JG72-H338

Affected Products

Glp