GHSA-7rqw-r5p3-ff92 GHSA-5qgv-9jcx-wph7 GHSA-h34m-gqcf-25cp
GLPI 11.0.9 fixes XSS via form illustration import and two access-control flaws
GLPI 11.0.9 fixes a high-severity XSS via form illustration import and two medium access-control flaws affecting GLPI 11.0.0 to before 11.0.9, plus GLPI 0.83 to before 10.0.27 and GLPI 9.5.0 to before 10.0.27. Upgrade to GLPI 11.0.9 or 10.0.27.
What happened
The first issue, GHSA-7rqw-r5p3-ff92, is a cross-site scripting flaw in form illustration import. An authenticated user with form import permissions can inject arbitrary content into a form's custom illustration through a JSON import and trigger XSS. GLPI rates this high severity with a CVSS 4.0 score of 8.6. It is reachable over the network, requires high privileges, and needs no additional user interaction.
The second issue, GHSA-5qgv-9jcx-wph7, allows any connected user to craft a request that changes the visibility of knowledge base items, reminders and RSS feeds, and therefore access their content. GLPI rates this medium severity with a CVSS 4.0 score of 5.3.
The third issue, GHSA-h34m-gqcf-25cp, allows an authenticated user to access followups, tasks or solutions generated from templates. Depending on the template configuration, this may leak information from tickets, problems or changes. GLPI rates this medium severity with a CVSS 4.0 score of 5.3.
None of the three advisories is listed in CISA's KEV, and GLPI has not stated that any of them has been publicly disclosed or exploited.
Who is affected
All three advisories affect GLPI 11.0.0 to before 11.0.9. The form illustration import XSS, GHSA-7rqw-r5p3-ff92, affects only those releases.
The knowledge base, reminder and RSS feed visibility flaw, GHSA-5qgv-9jcx-wph7, affects GLPI 0.83 to before 10.0.27 and GLPI 11.0.0 to before 11.0.9.
The template followups, tasks and solutions access flaw, GHSA-h34m-gqcf-25cp, affects GLPI 9.5.0 to before 10.0.27 and GLPI 11.0.0 to before 11.0.9.
These functions sit within GLPI's form import, knowledge base, reminder, RSS feed and template-based ticket, problem and change features.
What to do now
- Upgrade installations running GLPI 11.0.0 to before 11.0.9 to GLPI 11.0.9. This resolves all three advisories.
- For installations affected by the two access-control flaws on older releases — GLPI 0.83 to before 10.0.27 for GHSA-5qgv-9jcx-wph7, and GLPI 9.5.0 to before 10.0.27 for GHSA-h34m-gqcf-25cp — upgrade to GLPI 10.0.27. GHSA-7rqw-r5p3-ff92 is not listed as affecting those older releases.
- GLPI has not published workarounds for these issues.
- Until the upgrade is applied, restrict GLPI access to trusted users and review permissions for form import and for knowledge base, reminder and RSS feed features.
How to detect it
GLPI has not published indicators of compromise for these issues. Review accounts with form import permissions and look for unexpected visibility changes to knowledge base items, reminders or RSS feeds, and for unusual access to followups, tasks or solutions generated from templates. Check imported form illustrations for unexpected script or HTML content.
Beyond the patch
These are the injection and access-control issues a penetration test and hardening review is designed to find before a patch forces a scramble. After upgrading, Implementation & Assessment Services can verify the patched paths and your GLPI access model. Because GLPI's update cycle is the real exposure window, tracking this self-hosted application in Supply Chain Defense & Third-Party Risk helps you notice the next fix when it lands.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| GHSA-7rqw-r5p3-ff92 GLPI | 11.0.0 – < 11.0.9 | 11.0.9 .9 |
| GHSA-5qgv-9jcx-wph7 GLPI | 0.83 – < 10.0.27 11.0.0 – < 11.0.9 | 10.0.27 11.0.9 .27, 11.0.9 |
| GHSA-h34m-gqcf-25cp GLPI | 9.5.0 – < 10.0.27 11.0.0 – < 11.0.9 | 10.0.27 11.0.9 .27, 11.0.9 |