Cross-site scripting in GLPI - #VU129534
Published: September 24, 2019 / Updated: May 4, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the rich text field when rendering user-supplied content. A remote attacker can inject a specially crafted script payload to execute arbitrary script in a victim's browser.