GLPI is vulnerable to XSS and open redirection attacks through planning feature

CVE Details

Basic Information

Title GLPI is vulnerable to XSS and open redirection attacks through planning feature
Type cve
Published 2025-07-30T14:07:58.830Z
Modified 2025-07-30T14:07:58.830Z

Product Information

Vendor glpi-project
Product glpi
Version >= 9.1.0, < 10.0.19

CVSS Information

Base Score 6.5 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected Products

  • glpi-project glpi >= 9.1.0, < 10.0.19

Additional Information

CWE List CWE-80, CWE-601
Source GitHub_M

Description

GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.