CVE-2025-27514: falha de média gravidade em glpi-project glpi
GLPI is susceptible to Stored XSS attack through project's kanban
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 4.5epss 0.2%
probabilidade de exploração
0.2%top 92% das CVEs
exploração observada
nãonenhuma fonte reporta
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Produtos afetados
glpi-project · glpiCVEs relacionadas — glpi-project glpi
No mesmo produto, das mais perigosas para as menos.
CVE-2025-24799HIGHGLPI allows unauthenticated SQL injection through the inventory endpointEPSS 86.7%CVE-2020-15175HIGHUnauthenticated File Deletion in GLPIEPSS 71.5%CVE-2023-46727HIGHGLPI SQL injection through inventory agent requestEPSS 67.7%CVE-2024-29889HIGHGLPI contains an SQL injection through the saved searchesEPSS 63.0%CVE-2024-31456HIGHGLPI contains an authenticated SQL injectionEPSS 59.1%CVE-2024-27096HIGHSQL Injection in through the search engineEPSS 58.8%