CVE-2025-26626: GLPI Inventory Plugin vulnerable to reflective Cross-site Scripting
The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 are vulnerable to reflective cross-site scripting, which may lead to executing javascript code. Version 1.5.0 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPI Inventory Pluginto a version that resolves this vulnerability.Fixed in 1.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26626?
CVE-2025-26626 is classified as a medium severity vulnerability due to the potential for reflective cross-site scripting.
How do I fix CVE-2025-26626?
To fix CVE-2025-26626, update the GLPI Inventory Plugin to version 1.5.0 or later.
What types of applications are affected by CVE-2025-26626?
CVE-2025-26626 affects the GLPI Inventory Plugin versions prior to 1.5.0.
What consequences can arise from CVE-2025-26626?
Exploiting CVE-2025-26626 can allow attackers to execute arbitrary JavaScript code in the context of the victim's browser.
When was CVE-2025-26626 reported?
CVE-2025-26626 was reported and acknowledged prior to the release of the patch in version 1.5.0 on February 25, 2025.