Cross-Site Scripting Vulnerability in GLPI by GLPI Project
CVE-2025-59935
6.5MEDIUM
What is CVE-2025-59935?
A cross-site scripting vulnerability exists in GLPI, where an unauthenticated user can inject an XSS payload through the inventory endpoint. This affects all versions from 10.0.0 up to 10.0.20. To mitigate this issue, users are advised to upgrade to version 10.0.21, which includes a security patch addressing this vulnerability.
Affected Version(s)
glpi >= 10.0.0, < 10.0.21
