Improper Encoding or Escaping of Output in GLPI - CVE-2026-55214
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a user's browser.
The vulnerability exists due to improper encoding or escaping of output in supplier website fields when rendering the item's suppliers list. A remote privileged user can store a malicious script payload in a supplier website field to execute arbitrary script code in a user's browser.
User interaction is required to open the item's suppliers list.