PT-2026-99069 · Glpi · Glpi
CVE-2026-53610
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GLPI versions 11.0.0 through 11.0.7
Description
An attacker can craft a URL for a dashboard that reflects attacker-controlled markup due to insufficient output encoding. A user who opens this crafted URL triggers reflected cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites and executed in the victim's browser.
Recommendations
Update to version 11.0.8.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glpi