Description

GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user. Version 10.0.18 contains a fix for the issue.

INFO

Published Date :

2025-02-25T15:43:34.919Z

Last Modified :

2025-02-25T19:12:43.921Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-21627 vulnerability.

Vendors Products
Glpi-project
  • Glpi
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-21627.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact