Back to CVE List

CVE-2026-42321

Vulnerability Description

GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-79
Source
NVD
Vendor
glpi-project
Product
glpi

External References

Discussion (0)

Add Comment

No comments yet. Be the first!