#VU125057 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GLPI - CVE-2025-52897
Published: April 7, 2026
GLPI
glpi-project
Description
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of script-related html tags in a web page in the planning feature when handling a malicious link. A remote attacker can send a specially crafted link to execute arbitrary script in the victim's browser.
User interaction is required to open the crafted link.