First published: Fri Mar 14 2025(Updated: )
The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software package. Versions prior to 1.5.0 are vulnerable to reflective cross-site scripting, which may lead to executing javascript code. Version 1.5.0 fixes the issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI Inventory Plugin | <1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26626 is classified as a medium severity vulnerability due to the potential for reflective cross-site scripting.
To fix CVE-2025-26626, update the GLPI Inventory Plugin to version 1.5.0 or later.
CVE-2025-26626 affects the GLPI Inventory Plugin versions prior to 1.5.0.
Exploiting CVE-2025-26626 can allow attackers to execute arbitrary JavaScript code in the context of the victim's browser.
CVE-2025-26626 was reported and acknowledged prior to the release of the patch in version 1.5.0 on February 25, 2025.