CVE-2026-53610: GLPI: Reflected XSS in dashboards
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers reflected cross-site scripting in the dashboard. This issue is fixed in version 11.0.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.8
Event History
Frequently Asked Questions
Who is exposed to this issue?
GLPI installations running versions from 11.0.0 through 11.0.8 are affected. Exploitation requires a user to open an attacker-crafted dashboard URL.
What does an attacker need to exploit it?
The attacker needs to craft a dashboard URL containing attacker-controlled markup and persuade a user to open it. The cross-site scripting payload executes when the crafted URL is opened.
How can this be remediated?
Upgrade GLPI to the fixed version identified as 11.0.8. The provided data does not specify an alternative mitigation for installations that cannot be patched immediately.