GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| Vendors & Products |
Glpi-project
Glpi-project glpi |
Tue, 16 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch. | |
| Title | GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-16T17:15:24.435Z
Reserved: 2025-09-23T14:33:49.505Z
Link: CVE-2025-59935
Updated: 2025-12-16T17:15:19.911Z
Status : Received
Published: 2025-12-16T17:16:10.137
Modified: 2025-12-16T17:16:10.137
Link: CVE-2025-59935
No data.
OpenCVE Enrichment
Updated: 2025-12-16T20:45:09Z