GLPI Reflected Cross-Site Scripting Vulnerability in Search Page

Vulnerability

A reflected cross-site scripting vulnerability has been identified in GLPI versions prior to 10.0.18. This issue allows a malicious link to be crafted that performs a reflected XSS attack on the search page. If anonymous ticket creation is enabled, the attack can be executed by an unauthenticated user.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Remediation

Users are advised to upgrade to GLPI version 10.0.18, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM