CVE-2025-21627: GLPI Cross-site Scripting vulnerability
GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted to perform a reflected XSS attack on the search page. If the anonymous ticket creation is enabled, this attack can be performed by an unauthenticated user. Version 10.0.18 contains a fix for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21627?
CVE-2025-21627 is considered a critical vulnerability due to its potential for unauthenticated exploitation via reflected XSS.
How do I fix CVE-2025-21627?
To fix CVE-2025-21627, update GLPI to version 10.0.18 or later.
Who is affected by CVE-2025-21627?
CVE-2025-21627 affects all versions of GLPI prior to 10.0.18.
What type of attack does CVE-2025-21627 allow?
CVE-2025-21627 allows for a reflected XSS attack on the search page when anonymous ticket creation is enabled.
Can CVE-2025-21627 be exploited by authenticated users?
CVE-2025-21627 can be exploited by unauthenticated users if anonymous ticket creation is enabled.