← voltar
CVE-2025-52897mediumCWE-601CWE-80

GLPI is vulnerable to XSS and open redirection attacks through planning feature

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 6.5epss 0.2%
probabilidade de exploração
0.2%top 88% das CVEs
exploração observada
nãonenhuma fonte reporta
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Produtos afetados
glpi-project · glpi